3 ms·
I think your missing the part of the bug report where Firefox is REUSING the existing TLS connection, which was established with a completely different SNI. If
by voidwtf 4y ago
I think your missing the part of the bug report where Firefox is REUSING the existing TLS connection, which was established with a completely different SNI.
If I have a load balancer handling all these connections, and I routed a connection through to static-backend-1 then Firefox “cheerfully” decided to reuse this connection for api.host.tld, how is my load balancer which has already handed off the connection to static-backend-1 going to do anything about that?
- tialaramex 4y agoMozilla are doing this for HTTP/2 which transports the entire URI, not like HTTP/1.0 where people just figure hey, I needn't send the server's name. So, the request for api.host.tld says "api.host.tld" on it. If your static server receives this request, but isn't able to service api.host.tld requests the HTTP/2 specification provides an HTTP error code to return 421, saying, oops, I can't help you with that - and the specification tells clients that in this case they might try asking via another route.