On Jun 5, 2006, at 9:01 AM, Titi Ala'ilima wrote:

You can't get around the one IP per hostname/cert though (unless you were comfortable with using non-standard ports, which I wouldn't be).


RFC 2817 defines TLS upgrade, which would allow this. That's the good news; the bad news is that while it's supported by Firefox and recent versions of Apache, it's not supported by MSIE (nor will it be in Vista). However, according to MSFT, RFC 3546 (http://www.ietf.org/rfc/rfc3546.txt) *will* be supported in IE7 (reference: http://blogs.msdn.com/ie/archive/2006/04/17/577702.aspx#578776). Support for TLS Extensions is (according to the Intarweb) currently rolled into openssl-0.9.9-dev and GnuTLS (and, by extension, Apache's mod_gnutls) also claims to support it.

Noah Robin
Sr. System Administrator, AOL
703.265.2925
#include <remarks/witty.h>


-- AOLserver - http://www.aolserver.com/

To Remove yourself from this list, simply send an email to <[EMAIL PROTECTED]> with the body of "SIGNOFF AOLSERVER" in the email message. You can leave the Subject: field of your email blank.

Reply via email to