4 ms·
Yes, I should not have said the certificate, I'd meant SNI. Thank you for correcting.
by staticassertion 4y ago
Yes, I should not have said the certificate, I'd meant SNI. Thank you for correcting.
- tialaramex 4y agoHowever, the SNI (prior to ECH) just tells us who the Client said they wanted to talk to when connecting. Suppose the client calls 10.20.30.40, and they announce they want to talk to legit.example which is fine. The server sends a certificate (which the ISP doesn't see) and that certificate says it's valid for legit.example and for naughty.example. Now the client is allowed, in HTTP/2 and HTTP/3 to say "Actually I want https://naughty.example/stuff https://naughty.example/stuff" and although the server isn't obligated to have that answer because the client said it originally wanted to talk to legit.example not naughty.example it often can answer and will. The client has a certificate showing this server is entitled to answer this question, and now it has an answer, so it's done. [If the HTTPS server can't answer or doesn't want to for any reason, the HTTP error code for this scenario, where somebody asked you about a name for which you have a certificate but aren't actually able to answer questions, is 421 Misdirected].
- staticassertion 4y agoInteresting, I'd never considered such a scenario. Thank you.