The router doesn't have wildcard cert support now. I believe this was a somewhat recent change and a side effect of allowing you to have a TLS only route without getting the default HTTP route. Until openshift/origin#1779 lands we'll need to generate a cert to demo TLS.