Let's encrypt now supports wildcard certificates, so one certificate secures all subdomains.

