3 ms·
If you have an SSL intercepting proxy then you don't need SNI support on the clients.
by omh 10y ago
If you have an SSL intercepting proxy then you don't need SNI support on the clients.
- jusob 10y agoIf this is an explicit proxy, this is true. But with a transparent proxy, SNI would still be needed to know what domain name is going to be requested.
- userbinator 10y agoWith HTTPS, the Host: header, which is precisely what SNI was designed as a use-case for, can be used.
- jusob 10y agoBut you see the Host header after the TLS handshake, after the certificate was sent. The poitn of SNI is to indicate the host header during the TLS handshake so that you get the right certificate. HTTP with the host header is one layer up. Again, this is for transparent proxy where no CONNECT is being sent.