3 ms·
No, proper fronting is when you mismatch Host: header and SNI. It takes a bit more than just editing /etc/hosts, which results in TLS error (as grandparent ment
by throw_a_grenade 2y ago
No, proper fronting is when you mismatch Host: header and SNI. It takes a bit more than just editing /etc/hosts, which results in TLS error (as grandparent mentioned), but editing /etc/hosts cannot be disabled by CDN.
- EE84M3i 2y agoI agree that's not proper domain fronting, but one point is that CDNs can and absolutely do restrict certain SNI/Host/sites to subsets of their IPs. It's not necessarily the case that if you can connect to one CDN node you can connect to all the sites that CDN serves.
- jesprenj 2y agoOP here. It doesn't work anymore: Requested host does not match any Subject Alternative Names (SANs) on TLS certificate [d22c2cdf866a373f3648c0d7c30f9399e974d07c8c5417566ff11059a06f5b40] in use with this connection. Visit https://docs.fastly.com/en/guides/common-400-errors#error-421-misdirected-request https://docs.fastly.com/en/guides/common-400-errors#error-42... for more information. But I'm just doing this from memory, it's possible I did something else a years ago.