Hello Bill,

Friday, April 13, 2001, 10:16:35 AM, Bill Gerrard wrote:

>> It is a requirement of the SSL protocol that it cannot share the same
>> IP address and port combination.

> The cert is tied to the domain name not the IP address.

I'm not talking about the cert's limitations, but the SSL protocol
itself.  The SSL Protocol cannot support sharing the same IP address
and port combination across more than one virtual host.

It doesn't matter what web server software you are running.

>> I've generally not found this to be a problem, however.  Very very few
>> sites have users actually type in https://theirsite.com/  Visitors
>> instead come into the SSL site via a link on the standard site.

> I'm not sure I understand what you are saying.  The web server can't tell
> the difference between a user typing https://somesite into their browser
> versus selecting a link to https://somesite from a web page.


> Apache has no problem with name-based virtual hosting and SSL.  We do it all
> the time.

No, you don't.  It's not possible.

> Microsoft's IIS by design doesn't support name based virtual hosts on ports
> other than 80.  They even have a KB article on the subject.  I found this
> out a few weeks ago when helping a friend trying to get SSL running on there
> second virtual host.

No webserver supports name based virtual hosting via SSL.

-- 
Best regards,
 William                            mailto:[EMAIL PROTECTED]


Reply via email to