Re: SSL proxy

Cuesta Gilles <[email protected]> Fri, 11 Jul 2008 12:44:34 +0200
Newsgroups gmane.comp.apache.mod-ssl.user
Message-ID <[email protected]>
Eckard Wille a écrit :
> Cuesta Gilles schrieb:
>> I thought that using wildcard or multi-cn certificates will work ?
>
> No.
>
>> In this case, only one certificate is needeed for a range of Vhost
>
> If you only have one ip this won't make things better because virtual 
> hosting is still not possible. Wildcard certs do not enable vHosting 
> because the ssl handshake still takes place before the http host 
> header can be evaluated. They were offered by CAs to make it easier 
> for admins so they wouldn't have to fiddle around with dozens of certs 
> and their validity management in a masshosting environment or for 
> subdomains.
>

So what about this ?
"*MULTIPLE CN (SAN) SERVER CERTIFICATES*

This type of certificate (also called /Subject Alternative Name/ (SAN) ) 
enables to secure not only one website but a large number of sites (a 
list of sites) hosted on a shared infrastructure (server with multiple 
names, reverse proxy). Ideal to secure multiple brands of a corporation. 
One certificate per hardware is required."

http://www.tbs-certificats.com/index.html.en

-- 
Gilles CUESTA - Logiciels Libres
69139920
signature.asc (application/pgp-signature, 252 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFIdzmS545quQSHen8RAha4AKCVFSOS7NlxqUKMdHC9uI+Df3tlZACgkPyQ
W/Q8R0u54ICG9FsBnrO/JPY=
=/rrm
-----END PGP SIGNATURE-----