Re: SSL proxy
Cuesta Gilles <[email protected]> Fri, 11 Jul 2008 12:44:34 +0200
| Newsgroups | gmane.comp.apache.mod-ssl.user |
|---|---|
| Message-ID | <[email protected]> |
Eckard Wille a écrit : > Cuesta Gilles schrieb: >> I thought that using wildcard or multi-cn certificates will work ? > > No. > >> In this case, only one certificate is needeed for a range of Vhost > > If you only have one ip this won't make things better because virtual > hosting is still not possible. Wildcard certs do not enable vHosting > because the ssl handshake still takes place before the http host > header can be evaluated. They were offered by CAs to make it easier > for admins so they wouldn't have to fiddle around with dozens of certs > and their validity management in a masshosting environment or for > subdomains. > So what about this ? "*MULTIPLE CN (SAN) SERVER CERTIFICATES* This type of certificate (also called /Subject Alternative Name/ (SAN) ) enables to secure not only one website but a large number of sites (a list of sites) hosted on a shared infrastructure (server with multiple names, reverse proxy). Ideal to secure multiple brands of a corporation. One certificate per hardware is required." http://www.tbs-certificats.com/index.html.en -- Gilles CUESTA - Logiciels Libres 69139920
signature.asc
(application/pgp-signature, 252 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.6 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFIdzmS545quQSHen8RAha4AKCVFSOS7NlxqUKMdHC9uI+Df3tlZACgkPyQ W/Q8R0u54ICG9FsBnrO/JPY= =/rrm -----END PGP SIGNATURE-----