Re: [apache-ssl] Apache-SSL doesn't read multiple certs
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [apache-ssl] Apache-SSL doesn't read multiple certs



Rob Heittman wrote:
> 
> > The inherent problem is that SSL handshake (and therefore certificate
> > exchange) occurs _before_ any data is sent, including, of course, the
> > HTTP request which will determine the correct name-based virtual host.
> 
> D'oh!  Ignorance of the protocol is no excuse  :-)  I guess if it worked
> the way I was picturing, they'd be renaming it "Application Layer
> Security" instead of TLS.  Oh well, to the rubbish bin with that notion.
> Thanks!

OTOH, I do keep meaning to bring this one up on the TLS WG. I will while
I'm thinking about it.

Cheers,

Ben.

-- 
Ben Laurie            |Phone: +44 (181) 735 0686|  Apache Group member
Freelance Consultant  |Fax:   +44 (181) 735 0689|http://www.apache.org
and Technical Director|Email: ben@algroup.co.uk |
A.L. Digital Ltd,     |Apache-SSL author    http://www.apache-ssl.org/
London, England.      |"Apache: TDG" http://www.ora.com/catalog/apache