> 1) Buy (or license) 3 copies -- one for each machine -- of an SSL
certificate for each virtual host.

The certificate is matched by hostname.

www.foo.com has to match www.foo.com in the certificate.  If you do
subdomains than you can get a wildcard cert for *.foo.com


> 2) Have one IP address per virtual host.

Has to happen.  The SSL connection is made before the virtualhost entry is
touched.

> We have thought to use a dedicated machine that would sit in front of the
cluster and just 
> handle the SSL processing, but some employees here believe there is a
better way.


Thanks,
Dan

http://www.fastmail.fm

____________________
BYU Unix Users Group 
http://uug.byu.edu/ 
___________________________________________________________________
List Info: http://uug.byu.edu/cgi-bin/mailman/listinfo/uug-list


____________________
BYU Unix Users Group 
http://uug.byu.edu/ 
___________________________________________________________________
List Info: http://uug.byu.edu/cgi-bin/mailman/listinfo/uug-list

Reply via email to