Re: rfc2487bis-04: Failed negotiations & virtual hosting
Lutz Jaenicke <[email protected]> Tue, 17 Oct 2000 11:01:22 +0200
| Newsgroups | gmane.ietf.apps-tls |
|---|---|
| Organization | BTU Cottbus, Allgemeine Elektrotechnik |
| Message-ID | <[email protected]> |
On Thu, Oct 05, 2000 at 05:55:26PM -0700, Gregory Neil Shapiro wrote: > 2. As Paul Hoffman and I discussed at IETF, there may be a virtual hosting > problem that will necessitate a change. For example, smtp.gshapiro.net > does virtual hosting for about 50 domains. If a client expects the > certificate CN and the hostname to match, there needs to be some way to > communicate that information. HTTP has HTTP/1.1 or the Server: line to > indicate the requested server. SMTP will need the same if the server is > to be able to determine which certificate to send. Do you have something in mind? This item has been discussed some months ago without final conclusions. One possibility was to use the dNSName feature in the subjectAltName. This however requires, that whenever your virtually hosted domains change you need to aqcuire a new certificate. For a client to indicate the requested server I don't think this is possible within the existing protocol. At the time the STARTTLS command is issued, the server has not yet received a "RCPT TO:" command, so that this information cannot be used. An "easy" way to do it would be to extend STARTTLS to "STARTTLS required_target", but this would in fact change the protocol. And it would give away some of the privacy obtained as an eavesdropper could derive information about the email being sent. Unfortunately, no "required target" feature was designed into the TLS protocol... Best regards, Lutz -- Lutz Jaenicke [email protected] BTU Cottbus http://www.aet.TU-Cottbus.DE/personen/jaenicke/ Lehrstuhl Allgemeine Elektrotechnik Tel. +49 355 69-4129 Universitaetsplatz 3-4, D-03044 Cottbus Fax. +49 355 69-4153