swestrup: (Default)
[personal profile] swestrup
I spent the day looking into the whole virtual-name-hosting of https. What everyone has been saying is indeed true. It can't be done. There simply isn't a way permitted by the protocol to define a multiplex https port.

The reason for this is that the first thing that happens during the protocol is that the client asks 'Who are you?', and the server must respond with a certificate that contains its domain address. Since a multiplex port has no way of determining which domain its being asked to respond as, there's nothing it can reply that is safe.

So, it looks like my server is only going to get ONE https domain for now. The current version of http+tls, (which replaces https) solves that problem neatly, but no one has bothered to implement it yet.

January 2017

S M T W T F S
1234567
891011121314
15161718192021
22232425262728
293031    

Most Popular Tags

Page Summary

Style Credit

Expand Cut Tags

No cut tags
Page generated Dec. 26th, 2025 08:14 pm
Powered by Dreamwidth Studios