On 2/4/11 3:31 AM, Alokat wrote:
> On 02/03/2011 08:10 PM, Reindl Harald wrote:

>> AFAIK this is a problem that does not exist in the real world
>> We are hosting 200 mail domains and there is one hostname
>> and one certificate for all of them

> yeah I guess I will just use one certificate for all domains.
> But it would be cool if it would work. :-)

More than cool; our main server is setup with the "you'll use our host
name" approach so ssl works.  An inherited server has a large number of
domains that are all setup as "mail.domain.name", and the ssl cert
problem is one of the large barriers to getting people to use ssl.

It's something fixed with TLS/SNI (apparently OpenSSL 0.9.8f or later
supports it, though client side support is anyone's guess), but not
something I've had time to investigate and deploy yet.

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

Reply via email to