Re: rfc2487bis-04: Failed negotiations & virtual hosting

Lutz Jaenicke <[email protected]> Tue, 17 Oct 2000 11:01:22 +0200
Newsgroups gmane.ietf.apps-tls
Organization BTU Cottbus, Allgemeine Elektrotechnik
Message-ID <[email protected]>
On Thu, Oct 05, 2000 at 05:55:26PM -0700, Gregory Neil Shapiro wrote:
> 2. As Paul Hoffman and I discussed at IETF, there may be a virtual hosting
>    problem that will necessitate a change.  For example, smtp.gshapiro.net
>    does virtual hosting for about 50 domains.  If a client expects the
>    certificate CN and the hostname to match, there needs to be some way to
>    communicate that information.  HTTP has HTTP/1.1 or the Server: line to
>    indicate the requested server.  SMTP will need the same if the server is
>    to be able to determine which certificate to send.

Do you have something in mind? This item has been discussed some months
ago without final conclusions.

One possibility was to use the dNSName feature in the subjectAltName.
This however requires, that whenever your virtually hosted domains change
you need to aqcuire a new certificate.

For a client to indicate the requested server I don't think this is
possible within the existing protocol. At the time the STARTTLS command
is issued, the server has not yet received a "RCPT TO:" command, so that
this information cannot be used. An "easy" way to do it would be to 
extend STARTTLS to "STARTTLS required_target", but this would in fact
change the protocol. And it would give away some of the privacy obtained
as an eavesdropper could derive information about the email being sent.
Unfortunately, no "required target" feature was designed into the TLS
protocol...

Best regards,
	Lutz
-- 
Lutz Jaenicke                             [email protected]
BTU Cottbus               http://www.aet.TU-Cottbus.DE/personen/jaenicke/
Lehrstuhl Allgemeine Elektrotechnik                  Tel. +49 355 69-4129
Universitaetsplatz 3-4, D-03044 Cottbus              Fax. +49 355 69-4153