Re: Multiple SSL listen statements and SNI

2016-11-11 Thread Igor Sysoev
On 11 Nov 2016, at 22:13, Dave Hayes wrote: > On 11/11/2016 10:49, Igor Sysoev wrote: >> Yes, *:443 matches all addresses except explicitly specified in listen >> directives with the same port 443. > > Ah! Thank you very much! This statement cleared up my confusion. I didn't see > this stateme

Re: Multiple SSL listen statements and SNI

2016-11-11 Thread Dave Hayes
On 11/11/2016 10:49, Igor Sysoev wrote: Yes, *:443 matches all addresses except explicitly specified in listen directives with the same port 443. Ah! Thank you very much! This statement cleared up my confusion. I didn't see this statement in any documentation, but I could have missed it. C

Re: Multiple SSL listen statements and SNI

2016-11-11 Thread Igor Sysoev
On 11 Nov 2016, at 20:29, Dave Hayes wrote: > On 11/11/2016 00:02, Igor Sysoev wrote: >> Please read this: >> http://nginx.org/en/docs/http/request_processing.html#mixed_name_ip_based_servers > > Thanks very much for your reply. I have read this before, but maybe I missed > something. In readin

Re: Multiple SSL listen statements and SNI

2016-11-11 Thread Dave Hayes
On 11/11/2016 00:02, Igor Sysoev wrote: Please read this: http://nginx.org/en/docs/http/request_processing.html#mixed_name_ip_based_servers Thanks very much for your reply. I have read this before, but maybe I missed something. In reading it again like you asked, I see this paragraph: "In th

Re: Multiple SSL listen statements and SNI

2016-11-11 Thread Igor Sysoev
On 11 Nov 2016, at 05:30, Dave Hayes wrote: > Hello. :) Please consider the following nginx setup: > > server { > # server 1 > listen 443 default_server ssl; > server_name ""; > ... > return 444; > } > > server { > # server 2 > listen 127.0.0.81:443 default_server ssl; > server_

Multiple SSL listen statements and SNI

2016-11-10 Thread Dave Hayes
Hello. :) Please consider the following nginx setup: server { # server 1 listen 443 default_server ssl; server_name ""; ... return 444; } server { # server 2 listen 127.0.0.81:443 default_server ssl; server_name ""; ... return 444; } server { # server 3