[prev in list] [next in list] [prev in thread] [next in thread] 

List:       ntp-hackers
Subject:    Re: [ntp:hackers] Using multiple SSL certs - Was: Why...
From:       Olaf Fraczyk <olaf () navi ! pl>
Date:       2009-06-10 7:46:27
Message-ID: 1244619987.20432.52.camel () venus ! local ! navi ! pl
[Download RAW message or body]

On Tue, 2009-06-09 at 22:10 -0400, Steve Kostecke wrote:
> Olaf Fraczyk said:
> 
> >So, if we want to have 1000 WWW sites with SSL support we need 1000 IPs.
> 
> That's not true. Subject Alternative names allow a certificate (and the
> associated IP address) to be used for multiple hostnames. Please see
> http://www.ietf.org/rfc/rfc4985.txt
> 
But it is of no use for the purpose I described. 
Nobody will make a certificate for different WWW sities belonging to
different companies. It makes sense eg. for 1 company that has a WWW
site with different names.

Company A hosts WWW sities for other companies: B,C,D,E......
Now B buys certificate, C buys certificate, and so on.
Then they upload their certificates to server at company A.
How would you like to combine it into 1 certificate? It is impossible.

Regards,

Olaf


> -- 
> Steve Kostecke <kostecke@ntp.org>
> NTP Public Services Project http://support.ntp.org/
> Public Key at http://support.ntp.org/Users/SteveKostecke
> 
-- 
Olaf Frączyk <olaf@navi.pl>
NAVI
http://www.navi.pl
http://www.ntp.navi.pl

_______________________________________________
hackers mailing list
hackers@lists.ntp.org
https://lists.ntp.org/mailman/listinfo/hackers

[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic