Home > Uncategorized > One HTTPS site per IP address… or may be not?

One HTTPS site per IP address… or may be not?

I randomly ran across SNI (aka RFC 4366) tonight. It’s a technology that has been under development since before 2000 that allows the client to tell the server what domain it’s visiting before the server sends the certificate. The history is fascinating!

The situation today is that SNI is not here yet. OpenSSL will support it starting in 0.9.9, but has it as a compile time option (default disabled) as of 0.9.8f. Apache may support in it’s next minor release (2.2.12), or maybe not… at least it’s in their trunk, so it will be released someday. I just installed the SNI patch on my Apache 2.2.11 server, and I’m going to try it out. IIS has no stated plan to support it or not. The other popular servers, like Cherokee, lighthttps, and nginx, support it today.

But, as usual, browser support is the limiting factor:

As usual, Internet Explorer is the limiting factor. You need *Vista* to use SNI, so given that IE6 still has a decent market share, and it’s 8 years old… it’s going to be at least 2017 before we can reliably host multiple HTTPS sites on the same IP address – and who knows about embedded browsers (like those in cell phones and PDAs). Perhaps using one IPv6 address per HTTPS site will be more practical before SNI is widely available… who knows.

Categories: Uncategorized Tags:
  1. April 5th, 2010 at 22:30 | #1
    No need to go nuts recompiling Apache. Just install the GnuTLS module for Apache, which already supports TLS-SNI out of the box. If you use Ubuntu, this is simple as apt-get install libapache2-mod-gnutls, although you do need to change the mod_ssl syntaxes to ones compatible with mod_gnutls.
  2. September 4th, 2010 at 14:41 | #2
    To have sales or new clients you should traffic for your web page or telephone. The internet site should be the pre-sale to your phone call or the sale towards the purchase button. In either event, you need to to drive persons there and also the only way you can do that is certainly by obtaining your web page recognized by the engines. If you would like support with that feel no cost to contact buy backlinks
  1. No trackbacks yet.