Subject: The mailing list for listmasters using Sympa
List archive
- From: Patrick von der Hagen <address@concealed>
- To: "address@concealed" <address@concealed>
- Subject: Re: [sympa-users] HTTPS with virtual robots?
- Date: Mon, 28 Jul 2008 10:43:54 +0200
Adam Bernstein schrieb:
>> what you say is true for http requests. However, https is not as easy,
>> because of the SSL protocol. See:
>> http://www.g-loaded.eu/2007/08/10/ssl-enabled-name-based-apache-virtual-hosts-with-mod_gnutls/
>
>
> Right, that's what I meant, this is always the problem with SSL. I
> always have to research it again to remind myself exactly why, but you
> need each SSL virtualhost to live on a different IP address (or a
> different TCP port); you can't used name-based virtual hosts with SSL.
> The one exception may be if you purchase a wildcard SSL cert, but that
> would only work for different hostnames within the same domain, while I
> need the same hostname in different domains.
Well, one could perhaps consider SNI (Server Name Indication, RFC 3546)
which should help running several hostnames with https on one IP. Recent
browsers should support it, and one shouldn't use older ones anyway, but
wheter or not this is a problem for you depends completely on your
customers. As long as SERVER_NAME is set correctly, SNI should be
transparent to sympa.
http://en.wikipedia.org/wiki/Https
Because SSL operates below http and has no knowledge of higher level
protocols, SSL servers can only strictly present one certificate for a
particular IP/port combination[citation needed]. This means that in most
cases it is not feasible to use name-based virtual hosting with https.
RFC-3546 TLS Extensions describes a solution called Server Name
Indication (SNI), although support for is recent (Opera 8, Mozilla 1.8,
Internet Explorer 7 on Windows Vista, ...).[3][4]
--
CU,
Patrick.
Attachment:
smime.p7s
Description: S/MIME Cryptographic Signature
-
[sympa-users] HTTPS with virtual robots?,
Adam Bernstein, 07/24/2008
-
Re: [sympa-users] HTTPS with virtual robots?,
Patrick von der Hagen, 07/25/2008
-
Re: [sympa-users] HTTPS with virtual robots?,
Adam Bernstein, 07/25/2008
-
Re: [sympa-users] HTTPS with virtual robots?,
Adamec Vaclav, 07/26/2008
-
Re: [sympa-users] HTTPS with virtual robots?,
Tornóci László, 07/26/2008
-
Re: [sympa-users] HTTPS with virtual robots?,
Adam Bernstein, 07/26/2008
- Re: [sympa-users] HTTPS with virtual robots?, Patrick von der Hagen, 07/28/2008
-
Re: [sympa-users] HTTPS with virtual robots?,
Adam Bernstein, 07/26/2008
-
Re: [sympa-users] HTTPS with virtual robots?,
Tornóci László, 07/26/2008
-
Re: [sympa-users] HTTPS with virtual robots?,
Adamec Vaclav, 07/26/2008
-
Re: [sympa-users] HTTPS with virtual robots?,
Adam Bernstein, 07/25/2008
- Re: [sympa-users] HTTPS with virtual robots?, Peter Langhans, 07/30/2008
-
Re: [sympa-users] HTTPS with virtual robots?,
Patrick von der Hagen, 07/25/2008
Archive powered by MHonArc 2.6.19+.