Tuesday, May 25, 2010

Re: [Geopriv] Security considerations for LIS discovery

The IP address is usually common (to many customers). I guess I can't say
for certainty how it works, but it's something that Apache does with
configuration.

Brian


On 5/25/10 10:57 AM, "Ray Bellis" <Ray.Bellis@nominet.org.uk> wrote:

>> "Doesn't scale"?
>>
>> The solution of "multiple subjectAltNames" doesn't work, but equipping the
>> ISP LIS with a separate credential for each of its customers does. Even
>> someone like Godaddy does that now for its customers. You get a cert, you
>> upload it, the HTTP server uses it. They probably host tens of thousands of
>> certs for different domains.
>
> And would they be doing that with one IP address per cert, or using TLS
> server name indication ?
>
> If the latter, how widely is it supported (at the client side) ?
>
> [serious question - I've not been involved in SSL site hosting for several
> years]
>
> Ray
>
>


_______________________________________________
Geopriv mailing list
Geopriv@ietf.org
https://www.ietf.org/mailman/listinfo/geopriv