Changes between Version 1 and Version 2 of TipAndDoc/network/httpd


Ignore:
Timestamp:
Nov 10, 2009 12:13:35 AM (14 years ago)
Author:
mitty
Comment:

--

Legend:

Unmodified
Added
Removed
Modified
  • TipAndDoc/network/httpd

    v1 v2  
    1414暗号を解読するためには先に証明書の交換を行う必要がありますね。 
    1515}}} 
    16  
    17  * ただし、全てのVirtualHostで同じワイルドカード証明書を指定すれば可能 
    1816 * [http://httpd.apache.org/docs/2.2/ssl/ssl_faq.html#vhosts2 Why is it not possible to use Name-Based Virtual Hosting to identify different SSL virtual hosts?] 
    1917   * It is possible, but only if using a 2.2.12 or later web server, built with 0.9.8j or later OpenSSL. This is because it requires a feature that only the most recent revisions of the SSL specification added, called Server Name Indication (SNI). 
    2018   * The reason is that the SSL protocol is a separate layer which encapsulates the HTTP protocol. So the SSL session is a separate transaction, that takes place before the HTTP session has begun. The server receives an SSL request on IP address X and port Y (usually 443). Since the SSL request did not contain any Host: field, the server had no way to decide which SSL virtual host to use. Usually, it just used the first one it found which matched the port and IP address specified. 
     19 
     20 * ただし、全てのVirtualHostで同じワイルドカード証明書を指定すれば可能