The SSL layer starts before the HTTP layer, therefore the HOST field is not passed until after the certificate is sent, that means the HTTP SSL server does not know what certificate to send.
Therefore it relies on the IP to know what certificate to send, and hence while using a wildcard you can use multiple domains on one IP because it will just send the wildcard for all of them.
There is a version of SSL that fixes this issue by passing the host on the SSL layer, but it is not widely supported.
IMHO, XP SP3 was arguably one of the best OS's that M$ was ever able to make (actually, I think WIN2K desktop was even better in terms of resource usage and stability, but didn't have the automatic device recognition of XP).
An nLite'd XP SP3 running as VM on top of a "real" OS (even on a laptop) is pretty good!
Don't forget how many people would request (and I believe have to pay for) the XP "downgrade" on PCs due to Vista.
[@joepie91 said](/discussion/comment/183487#Comment_183487): I have always been a pain in the ass about the security for pretty much anything, and will continue to do so here. -
So I decided I'd try SNI and went to get a free cert from StartSSL.
However their login page directs me to https://auth.startssl.com/
which doesn't even load with ... an SSL error, lawl. Anyone else can access it?
@rm_: You need your authentication certificate on your browser (which is how they verify you for your account). This can be made using the registration button :P
[@joepie91 said](/discussion/comment/183487#Comment_183487): I have always been a pain in the ass about the security for pretty much anything, and will continue to do so here. -
@rm_ said: So I decided I'd try SNI and went to get a free cert from StartSSL.
However their login page directs me to https://auth.startssl.com/
which doesn't even load with ... an SSL error, lawl. Anyone else can access it?
Well, this has been discussed in many topics, StartSSL doesn't support Google Chrome, best browser to access their website is Firefox, and you have to install personal certification from StartSSL first ;)
Comments
Because
The SSL layer starts before the HTTP layer, therefore the HOST field is not passed until after the certificate is sent, that means the HTTP SSL server does not know what certificate to send.
Therefore it relies on the IP to know what certificate to send, and hence while using a wildcard you can use multiple domains on one IP because it will just send the wildcard for all of them.
There is a version of SSL that fixes this issue by passing the host on the SSL layer, but it is not widely supported.
Daniel.
http://en.wikipedia.org/wiki/Server_Name_Indication
I tried to explain it as simple as possible.
Daniel.
@MrLawoodle good point.
Time is good and also bad. Life is short and that is sad. Dont worry be happy thats my style. No matter what happens i won't lose my smile!
Yes, was an "x2" answer
And Win XP will be around for some years
People really should stop using windows xp. It's Rediculously old!
And ridiculously good.
Not sure how "it's old" is a reason to stop using it. Software doesn't rot over time.
Appreciate my posts/software/guides? Donate (PayPal/Flattr/Bitcoin): http://cryto.net/~joepie91/donate.html | irc.freenode.net #lowendbox
It took them so long to make XP stable no one wants to go through it again.
People should stop using Linux, its ridiculously old!
People should stop using Cars, they're ridiculously old!
People should stop using Jets, they're ridiculously old!
lalalala..logic!
@WhiteLabelHosting Is alive? 0_o
Don't forget breathing! People should stop breathing because you can die from oxygen poisoning!
@WhiteLabelHosting I think they mean "outdated"
I still think XP is great, I know loads of companies who use on workstations it because it's pretty stable.
Unix IO - VPS/Dedicated Server Offers & Deals, Provider Reviews, and Tutorials/Guides
Chat with us at irc.freenode.net // #unixio
@Jeffrey
IMHO, XP SP3 was arguably one of the best OS's that M$ was ever able to make (actually, I think WIN2K desktop was even better in terms of resource usage and stability, but didn't have the automatic device recognition of XP).
An nLite'd XP SP3 running as VM on top of a "real" OS (even on a laptop) is pretty good!
Don't forget how many people would request (and I believe have to pay for) the XP "downgrade" on PCs due to Vista.
Wasn't this discussion about SSL and IP's?
[Raymii.org](http://raymii.org) - [About Me](http://sparklingnetwork.nl) - [Need a VPS Control Panel?](http://z1s.org/) - [Need a VPS that doesn't suck?](http://clients.inceptionhosting.com/aff.php?aff=083)
[@joepie91 said](/discussion/comment/183487#Comment_183487): I have always been a pain in the ass about the security for pretty much anything, and will continue to do so here. -
XP is the best among desktop WIndows right now. Stable and low on resources.
Investing in the Philippines
Yes, and about how XP doesn't support SNI
@Raymii typical Let, nothing new.
Time is good and also bad. Life is short and that is sad. Dont worry be happy thats my style. No matter what happens i won't lose my smile!
Yes, but this is LET.
So I decided I'd try SNI and went to get a free cert from StartSSL. However their login page directs me to https://auth.startssl.com/ which doesn't even load with ... an SSL error, lawl. Anyone else can access it?
@rm_: You need your authentication certificate on your browser (which is how they verify you for your account). This can be made using the registration button :P
Try using this link dude: https://www.startssl.com/?app=12
Exactly
My SSL is from http://sslcertificaten.nl: https://raymii.org (and in runs clustered on 8 nodes hehe, so i'm wasting 8 IP's!)
[Raymii.org](http://raymii.org) - [About Me](http://sparklingnetwork.nl) - [Need a VPS Control Panel?](http://z1s.org/) - [Need a VPS that doesn't suck?](http://clients.inceptionhosting.com/aff.php?aff=083)
[@joepie91 said](/discussion/comment/183487#Comment_183487): I have always been a pain in the ass about the security for pretty much anything, and will continue to do so here. -
Well, this has been discussed in many topics, StartSSL doesn't support Google Chrome, best browser to access their website is Firefox, and you have to install personal certification from StartSSL first ;)
⌦ BudgetVPS: Where to find the cheapest VPS offer ⌦ DICHVU.IT: All about SSL - PositiveSSL from $7.4/year - EV SSL from $50/year ⌦ My blog: A small place of me :D
@giang We try to let them figure out how much StartSSL sucks on their own. It won't take long..
Unix IO - VPS/Dedicated Server Offers & Deals, Provider Reviews, and Tutorials/Guides
Chat with us at irc.freenode.net // #unixio
Low on security too.
Daniel.
@Asadhaider come on, it is FREE! You do not complain about something that you are not paying for.
Any way, awesome detailing going on. Carry on!
Time is good and also bad. Life is short and that is sad. Dont worry be happy thats my style. No matter what happens i won't lose my smile!