4 ms·
That's a flaw in dot-net's SslStream library. You don't get an opportunity to know what host the client is expecting before selecting the cert for this session.
by billpg 4y ago
That's a flaw in dot-net's SslStream library. You don't get an opportunity to know what host the client is expecting before selecting the cert for this session. Reading discussions around this issue usually settle on reading and parsing the "ClientHello" to extract the SNI name, and then hacking the ClientHello back into the incoming stream so TLS code can read it.