This config solved problem for me with wildcard cert https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_trusted_certificate