Rob Heittman wrote:
>
> > The inherent problem is that SSL handshake (and therefore certificate
> > exchange) occurs _before_ any data is sent, including, of course, the
> > HTTP request which will determine the correct name-based virtual host.
>
> D'oh! Ignorance of the protocol is no excuse :-) I guess if it worked
> the way I was picturing, they'd be renaming it "Application Layer
> Security" instead of TLS. Oh well, to the rubbish bin with that notion.
> Thanks!
OTOH, I do keep meaning to bring this one up on the TLS WG. I will while
I'm thinking about it.
Cheers,
Ben.
--
Ben Laurie |Phone: +44 (181) 735 0686| Apache Group member
Freelance Consultant |Fax: +44 (181) 735 0689|http://www.apache.org
and Technical Director|Email: ben@algroup.co.uk |
A.L. Digital Ltd, |Apache-SSL author http://www.apache-ssl.org/
London, England. |"Apache: TDG" http://www.ora.com/catalog/apache