Commit ad583d1b authored by Richard Bowen's avatar Richard Bowen
Browse files
that wildcard certs and subjectAltName are viable solutions.


git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.2.x@1296921 13f79535-47bb-0310-9956-ffa450edef68
parent 3ac418ba
Loading
Loading
Loading
Loading
+12 −1
Original line number Diff line number Diff line
@@ -762,7 +762,13 @@ error when connecting to my newly installed server?</a></h3>
    Apache has to know the <code>Host</code> HTTP header field. To do this, the
    HTTP request header has to be read. This cannot be done before the SSL
    handshake is finished, but the information is needed in order to 
    complete the SSL handshake phase. Bingo!</p>
    complete the SSL handshake phase. See the next question for how to
    circumvent this issue.</p>

    <p>Note that if you have a wildcard SSL certificate, or a
    certificate that has multple hostnames on it using subjectAltName
    fields, you can use SSL on name-based virtual hosts without further
    workarounds.</p>


<h3><a name="vhosts2" id="vhosts2">Why is it not possible to use Name-Based
@@ -778,6 +784,11 @@ Virtual Hosting to identify different SSL virtual hosts?</a></h3>
    feature that only the most recent revisions of the SSL
    specification added, called Server Name Indication (SNI).</p>

    <p>Note that if you have a wildcard SSL certificate, or a
    certificate that has multple hostnames on it using subjectAltName
    fields, you can use SSL on name-based virtual hosts without further
    workarounds.</p>

    <p>The reason is that the SSL protocol is a separate layer which
    encapsulates the HTTP protocol. So the SSL session is a separate 
    transaction, that takes place before the HTTP session has begun. 
+12 −1
Original line number Diff line number Diff line
@@ -771,7 +771,13 @@ error when connecting to my newly installed server?</title>
    Apache has to know the <code>Host</code> HTTP header field. To do this, the
    HTTP request header has to be read. This cannot be done before the SSL
    handshake is finished, but the information is needed in order to 
    complete the SSL handshake phase. Bingo!</p>
    complete the SSL handshake phase. See the next question for how to
    circumvent this issue.</p>

    <p>Note that if you have a wildcard SSL certificate, or a
    certificate that has multple hostnames on it using subjectAltName
    fields, you can use SSL on name-based virtual hosts without further
    workarounds.</p>
</section>

<section id="vhosts2"><title>Why is it not possible to use Name-Based
@@ -787,6 +793,11 @@ Virtual Hosting to identify different SSL virtual hosts?</title>
    feature that only the most recent revisions of the SSL
    specification added, called Server Name Indication (SNI).</p>

    <p>Note that if you have a wildcard SSL certificate, or a
    certificate that has multple hostnames on it using subjectAltName
    fields, you can use SSL on name-based virtual hosts without further
    workarounds.</p>

    <p>The reason is that the SSL protocol is a separate layer which
    encapsulates the HTTP protocol. So the SSL session is a separate 
    transaction, that takes place before the HTTP session has begun.