this is a reasonable argument, except it's generally considered best practise not to share private keys across servers (most CAs explicitly forbid this in their deeply buried policy files), which also rules out wildcards.
StartCom is appealing as they'll issue as many certificates as you want for a one-off fee.
so I had protected my service against parts of it being compromised, but then I was screwed over completely by heartbleed.
I think drdaeman meant _certificates_ and not _servers_. One certificate can be used on multiple servers, but you can't create multiple certificates “for free“ on Comodo,Gandi or GlobalSSL. You're charged for every cert.
I'm using StartSSL verified, it costed me 99$ (personal verification) plus 99$ (company certification), and I can create any certificate I want, at any time, valid for two years and wildcard included.
Since my company provides custom subdomains for clients, and every client can have multiple subdomains on his own subdomain, we can't afford the price for every client. (I know we should charge them, but this issue is out of my hand).
The 25$ revocation fee sucks, yeah.. but StartSSL has his advantages too.
StartCom is appealing as they'll issue as many certificates as you want for a one-off fee.
so I had protected my service against parts of it being compromised, but then I was screwed over completely by heartbleed.
50 certs? that'll be $1250