-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Mike Burger wrote:

>To my knowledge, there is no way around it.  Currently, secure certs are 
>issued for specific IPs.  You can't really have more than one site with 
>the same IP and expect the certs to work, properly.

Right.  

This snip is from misc@openbsd, and is credited to Ben Laurie from the
Apache-SSL list:

`The issue is that the certificate presented by the server can only be
selected on the basis of stuff that's known as soon as the socket is  
connected (i.e. before any data exchange). The only useful information
available is the server IP and port number, so in order to present the
right certificate, you need a unique IP/port for each secure server.'

- -d

- -- 
David Talkington

PGP key: http://www.prairienet.org/~dtalk/0xCA4C11AD.pgp

-----BEGIN PGP SIGNATURE-----
Version: PGP 6.5.8
Comment: Made with pgp4pine 1.75-6

iQA/AwUBPKEDor9BpdPKTBGtEQK3rgCfaVwYb+UwHUj+kv9av+laIkxi5RsAoIH8
/awIB9Rjwetyxs2teyPIgbiO
=163N
-----END PGP SIGNATURE-----




_______________________________________________
Redhat-list mailing list
[EMAIL PROTECTED]
https://listman.redhat.com/mailman/listinfo/redhat-list

Reply via email to