Dave Townsend wrote:
Nelson B wrote:
There is no unique IP address required any more.  Modern TLS implementations
like the one in Mozilla products, allow the client and server to negotiate
the host name over the SSL connection, before the server presents its cert,
So that the server can pick the right cert.  It's good old virtual hosting,
done with https.  Works well.

Ah interesting, I was under the impression that bug 276813 was required for that sort of thing. I shall have to take a look over some popular hosts to see whether they offer this. Out of interests besides Mozilla do other browsers support this, IE? Safari? Opera?

To all of my knowledge this works only if the various domain names are bundled in one certificate as DSN extensions. I'm not aware that one can host multiple certificates and multiple hosts on one and same IP address and port (443).

--
Regards

Signer:      Eddy Nigg, StartCom Ltd.
Jabber:      [EMAIL PROTECTED]
Phone:       +1.213.341.0390

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

_______________________________________________
dev-tech-crypto mailing list
dev-tech-crypto@lists.mozilla.org
https://lists.mozilla.org/listinfo/dev-tech-crypto

Reply via email to