Koozali.org: home of the SME Server

SSL and virtual domains, how does SME do it?

ryan

SSL and virtual domains, how does SME do it?
« on: January 12, 2006, 08:42:58 PM »
I am playing with Apache on Centos4.  I have setup virtual domains on a test Centos4 box which will not work with SSL....redhat.com and apache.org confirm SSL is not possible with Virtual "Name  based hosts" using the same IP.  

Well, my SME 6 box does it.  I have several virtual sites all listening on the same IP address.  SSL connections to these the virtual sites do work.  Each virtual site is using the same SSL certificate on the SME server.  Can this capability be duplicated on default Centos & Apache without too much pain?

E-smith scripting=magic?

Ryan

Offline CharlieBrady

  • *
  • 6,918
  • +3/-0
Re: SSL and virtual domains, how does SME do it?
« Reply #1 on: January 12, 2006, 11:27:37 PM »
Quote from: "ryan"
I am playing with Apache on Centos4.  I have setup virtual domains on a test Centos4 box which will not work with SSL....redhat.com and apache.org confirm SSL is not possible with Virtual "Name  based hosts" using the same IP.
...
Well, my SME 6 box does it.


Which means that you've misinterpreted, or the documentation you've studied is incorrect.
You haven't quoted or provided a reference URL so we can't judge for ourselves, but "SSL is not possible ..." is plainly not true. What is true, however, is that SSL with virtual named hosts *and different certificates - which correctly match the named virtual hosts* is not possible.

Quote

Each virtual site is using the same SSL certificate on the SME server.


Exactly. Often this is not what people want, but it's all that is possible.

ryan

SSL and virtual domains, how does SME do it?
« Reply #2 on: January 12, 2006, 11:48:36 PM »
Thanks for the clarification Charlie.  I need to continue researching how to apply a single SSL cert. to multiple vitual sites on Centos.  SSL is desired to encrypt the traffic, using a self signed CA/server.crt.