4 ms·
Thank you for raising this! I work for a firewall vendor myself and its drives us mad when competition uses the word URL when they can only look at SNI in a TLS
by new23d 6y ago
Thank you for raising this! I work for a firewall vendor myself and its drives us mad when competition uses the word URL when they can only look at SNI in a TLS handshake. By competition I mean most others are doing it too.
I guess one of the reasons they choose to say URL over FQDN or hostname is that the latter two are less likely what typical developers might venture out looking for - but I could be wrong. At least the requirements when they emerge would want URLs to be whitelisted and that is what the intercepting proxy world had been delivering.
- nhoughto 6y agoErgonomics of SNI / domain rules suck, you think it’s ok until you have to choose whether or not to whitelist all of SQS or something and you end up having giant holes in your firewall because you can’t be specific enough and few services cater to those behind proxies..