From: Nick Sullivan <[email protected]>

> Consider a CDN with millions of domains sharing ECH infrastructure. The 
> "alias set" is the set of domains that share a given ECH configuration.

OK, but why are there multiple alias sets?

For this use case to make sense, it seems to me that we need all of the 
following to be true:

* The operator has multiple alias sets on the same IP address(es).
* The operator wishes for all of these alias sets to form a single anonymity 
set.
* The operator is not able to merge the alias sets (i.e. using a single 
ECHConfig).

Why would an operator ever be in this position?  Surely if the operator wants 
to create a unified anonymity set, they can already do this by establishing a 
single alias set (i.e. a single ECHConfig)?

--Ben
_______________________________________________
TLS mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to