Nay, server side they can implement a proper check if the cert actually own said product. If not it won't happen to let you get ahold of any other products.
Have to consider bandwidth requirements and speed, and how much it inconveniences real users vs. not. It's simpler for them to segregate eShop/Atum from sysmodule/Atum, and then just proceed to nuke CDN calls from banned certificates or dubious certificates. But yes, they could also do that if it proved suitably low-cost in resources.
If eShop/Atum is segregated behind a dauth check, none of this will work any more.











