What makes a certificate trusted
A browser trusts a certificate when it chains up to a root it already knows, has not expired and covers the name typed in the address bar. Servers must send the intermediate certificates as well as their own; a missing intermediate is the most common reason a site works in one browser and fails in another, or in curl.
Names are listed in the Subject Alternative Name field. A wildcard like *.example.com covers shop.example.com but not example.com itself, and not a.b.example.com.