This is the real issue with not allowing wildcard certs. If the rate limits were something that just cut in at abuse-levels, there'd be no need for them. Sites with per-user subdomains (to get security features like cookie isolation, break same-origin effects, etc) run into the limits really quickly, and must currently rely on a wildcard.
I've been calling this "the tumblr scenario", but people seem to think there's a way around it without just using another CA.
I've been calling this "the tumblr scenario", but people seem to think there's a way around it without just using another CA.