12 ms·
Ugh. Let's Encrypt will issue you a single certificate for multiple domains on the same server. It's easy to set up, too. It's not just for multiple subdomains
by WildUtah 10y ago
Ugh. Let's Encrypt will issue you a single certificate for multiple domains on the same server. It's easy to set up, too.
It's not just for multiple subdomains like sub1.example.com and sub2.exmaple.com. You can have any unrelated domains you want on the cert.
You don't need multiple IPs and you don't even need SNI with its legacy client compatibility problems (now mostly well past). Just get a certificate that covers all the domains you use.
There's no reason at all to suffer with the setup and security and resource problems of SNI or multiple IPs outside extreme scenarios.
- iDemonix 10y agoI was about to comment pretty much all of these points. As soon as I read about multiple IP's I wondered what was going on. I'm starting my own tech blog for similar articles, maybe I'll do a simpler example for my first post.
- bogomipz 10y agoIndeed this is what a SAN cert does. From Letsencrypt's FAQ: "Can I get a certificate for multiple domain names (SAN certificates or UCC certificates)? Yes, the same certificate can contain several different names using the Subject Alternative Name (SAN) mechanism. Source: https://letsencrypt.org/docs/faq/ https://letsencrypt.org/docs/faq/
- smarinov 10y agoThis is a solution if you don't care that anyone looking at the certificate would be able to directly see every single domain that you are hosting as part of your setup. Determined people would be still able to find it out, more or less, despite not having it handy in their web browser under the field for the certificate's Subject Alternative Name. However, there is nothing stopping you from issuing separate certificates for each domain (possibly with subdomains) and configuring your webserver appropriately with SNI. I have been using precisely Nginx to serve multiple HTTPS domains with certificates from Let's Encrypt since the first few weeks after it came out, so I am not sure why OP thinks it's strictly necessary to assign them separate IP addresses. Generally speaking, there is nothing wrong with that, and it is indeed a somewhat cleaner solution, if it wasn't for the IPv4 examples, oh my...
- zeta0134 10y agoI was under the impression that older clients wouldn't send the host header over HTTPS, making it impossible to determine the correct certificate to serve in a shared IP environment. Modern browsers all support SNI which prevents exactly this problem, but compromise by sending the hostname in plain text, which may be a privacy concern; this is something that's still up for debate: http://security.stackexchange.com/questions/86723/why-do-https-requests-include-the-host-name-in-clear-text http://security.stackexchange.com/questions/86723/why-do-htt... EDIT: I'm not sure what I was reading or who I was responding to. You mentioned this directly in your comment. Ignore my blathering, I'm tired. :)
- Buge 10y agoThey all send host headers over HTTPS (unless it's http2, because the protocol is different). But the host headers don't get sent until after the encrypted transport is fully setup. And to set up the encrypted transport, the server needs to send a certificate. So the server needs to send the certificate before it sees the host header. That's what SNI helps.
- Jaruzel 10y agoSNI doesn't work on Windows XP. "Who still use Windows XP?" I hear you ask? Just under 10% of all users[1]. Enough to make SNI problematic. In a few years time, we'll be OK, but not right now. --- [1] https://www.netmarketshare.com/operating-system-market-share.aspx?qprid=10&qpcustomd=0 https://www.netmarketshare.com/operating-system-market-share...
- tokenizerrr 10y agoOn internet explorer on Windows XP. Anyone on XP who uses Chrome or Firefox is just fine. If you are still using internet explorer on XP then you probably have other problems from all the malware that already installed itself on your computer.
- Jaruzel 10y ago
- phil21 10y ago> You don't need multiple IPs and you don't even need SNI with its legacy client compatibility problems (now mostly well past). Just get a certificate that covers all the domains you use. Horrible idea depending on your use case. If you are single-tenant, this might work out well for you. If you are multi-tenant then the information leak is pretty nuts, and not something I can see any of my customers being alright with. That and the whole idea of giving the public access to my customer list is pretty silly to me. Additionally in many environments the end-user can potentially access the private key on the server (think managed services environments) which is an obvious security hole. You'd think people would realize this, but in my experience they do not. In such cases you just let the private key walk out the door for every domain ever configured for that SSL certificate.
- ge96 10y agoNot sure if you'll see this or if it's directly related. I also domain map but on an Apache server, this is probably an excuse but while I realize Let's Encrypt is free, and although there is the 90-day thing that you could automate, I just go with the year-long $9.00 certificate for each domain. I was wondering though, since it's domain mapped, the root domain can bridge to other sites by subfolders eg. /var/www/html/main-domain | https://mainsite.com https://mainsite.com /var/www/html/main-domain/domain2 | https://somesite.com https://somesite.com /var/www/html/main-domain/domain3 | https://somesite2.com https://somesite2.com My question I could just easily try it, I'm not sure if it's related to what you mentioned where if you switch domains while logged into one if you'll lose session. I don't expect it to work. I just don't know what happens if people figured out "hey this ip is hosting multiple sites" and could figure out how to traverse each subfolder-site. My question sucks sorry. I'll have to try it out I guess, at least my stuff is for myself not dealing with other people's info/sites. This quesiton is related to information leak. I handle the domain mapping with virtualhosts. I also realized when you switch from say non-www to www (I saw you should stick with one) but when you do that you'll lose the session value so I imagine I'm safe. I actually just took down one site as it was a useless domain so I can't test the multiple ssl certificates at the moment. Yeap this question is a waste of time my bad.
- laumars 10y agoAny device that doesn't support SNI wouldnt be modern enough to support secure cyphers since weaknesses hav e been found in most of the older ones. Plus anything below TLS1.0 shouldn't be supported either (nor even TLS1.0 if you're running something where security really does matter). So you're better off dropping support for the aforementioned devices regardless of whether you choose to use SNI or not.
- scrollaway 10y agoAlso, plugging Caddy: https://caddyserver.com/ https://caddyserver.com/ I used to be a huge fan of nginx and I haven't touched it in a year now. I don't miss it, Caddy is fantastic and handles the Let's Encrypt stuff for me.
- _eht 10y agoCan anyone else speak to Caddy? My interest is peaked. I run several hundred thousand HTTP requests in a load balanced web cluster hourly, I'll do some reading, but has anyone else used it for high traffic?
- teach 10y agoI don't know anything about Caddy but for some reason I feel compelled to tell you that it's "piqued", not "peaked".
- skilgarriff 10y agoCaddy is pretty awesome. I use it to run my personal website (love that it can serve statically compiled Brotli assets out of the box). I maintain it's docker image here: https://github.com/ZZROTDesign/alpine-caddy https://github.com/ZZROTDesign/alpine-caddy :) Should be incredibly simple to set up!
- eicnix 10y agoHow does Caddy compare to nginx performance wise? I have a similar setup like you running on nginx. For loadbalancers I mainly care about performance and not usability of the configuration language.
- mholt 10y agoI hear this question a hundred different ways. What do you even mean by performance? There's so many dimensions to a web server.
- devwastaken 10y agoI can never take caddy seriously until they get serious about updates and start working with linux packages. When you have to do this: https://gist.github.com/Jamesits/2a1e2677ddba31fae62d022ef8aa54dc https://gist.github.com/Jamesits/2a1e2677ddba31fae62d022ef8a... That means your webserver is not going to receive updates until you re-do this manually each time, which is dangerous and not at all something you should be using proffessionally.
- mikeyjk 10y agoEven with AWSs load balancers? We are trying to solve this issue right now in house. Any recommendations/war stories/further reading would be greatly appreciated. Related forum post: https://forums.aws.amazon.com/message.jspa?messageID=520926 https://forums.aws.amazon.com/message.jspa?messageID=520926
- CaveTech 10y agoYou need to use SAN certificates to do this (Which LE will do). You just need to be comfortable with having every domain registered appearing on the certificate.
- cowholio4 10y agoYes! I do with NGINX using SNI (to server multiple ssl certs from the same IP) and using Proxy Protocol on the ELB to send the requests to NGINX. What you need to do is enable the proxy protocol on the ELB and then point to NGINX. http://docs.aws.amazon.com/elasticloadbalancing/latest/classic/enable-proxy-protocol.html http://docs.aws.amazon.com/elasticloadbalancing/latest/class... You need to also enable the proxy_protocol in nginx. server { listen 443 ssl proxy_protocol; ... } I'll write something up and share it. But hopefully this will help you in the short term.
- mikeyjk 10y agoThat would be very kind, thank you. I'm not the particular dev who has been doing the research, but I might read his notes later to catch up to what he perceived as the pitfalls of using ELB with LetsEncrypt.
- deleted 10y ago[deleted]
- mozumder 10y agoYou don't want to do this, as it's a privacy violation. It will let attackers know all the names of all the other websites you are serving, just by looking at one of those website. Do you want people to know that your server for www.donaldtrumpisgreat.com/www.hillaryclintonisgreat.com is also serving your company's homepage?
- gwu78 10y ago"... setup and security and resource problems of SNI..." As a user who really dislikes SNI, I would like to see someone write more about these problems.
- fenollp 10y agoExactly. I made this for exactly this usage: https://github.com/fenollp/nginx_ssl_compose https://github.com/fenollp/nginx_ssl_compose Just create a folder in ~/www for each host. It's been working great for around a year. Only interruption was due to docker destroying my containers during the upgrade of docker-engine. Great software guys...