Tuesday, May 25, 2010

Re: [Geopriv] Security considerations for LIS discovery

> "Doesn't scale"?
>
> The solution of "multiple subjectAltNames" doesn't work, but equipping the
> ISP LIS with a separate credential for each of its customers does. Even
> someone like Godaddy does that now for its customers. You get a cert, you
> upload it, the HTTP server uses it. They probably host tens of thousands of
> certs for different domains.

And would they be doing that with one IP address per cert, or using TLS
server name indication ?

If the latter, how widely is it supported (at the client side) ?

[serious question - I've not been involved in SSL site hosting for several
years]

Ray

_______________________________________________
Geopriv mailing list
Geopriv@ietf.org
https://www.ietf.org/mailman/listinfo/geopriv