SNI and SSL

Discussion in 'ISPConfig 3 Priority Support' started by bobpit, Feb 7, 2014.

  1. bobpit

    bobpit Member

    I have a vps and a single IP.

    I had installed ssl certificate for domain1. Now I have another domain, domain2 and I bought sl certificate too.

    I read in the manual that I can have only one ssl cert per IP, unless I use SNI. SNI is not supported in older browsers.

    IF I use SNI, what will happen to old not supported browsers (like in a windows XP system)? Will the site work in normal mode ie www.domain2.com? Will the old one (https://domain1.com) work flawesly? Will things become a mess?

    After things get working properly, I want to shift importance to the new site (www.domain2.com). So if things wok perfectly for one domain only, this should be domain2. How do I do this?
     
  2. till

    till Super Moderator Staff Member ISPConfig Developer

    Old browsers that does not support sni will show the content of the first website on your server (by domain name in alphabetical) order regardless of the domain that you entered in the browser URL bar.
     
  3. bobpit

    bobpit Member

  4. till

    till Super Moderator Staff Member ISPConfig Developer

    yes. asthe browser does not send the information that apache requires to identify the correct vhost over ssl.
     
  5. sjau

    sjau Local Meanie Moderator

    *
    * https://en.wikipedia.org/wiki/Server_Name_Indication

    Android 2.0 shouldn't be a problem anymore I think. However WinXP still is a problem.
     

Share This Page