Re: jailed virtual https, anyone?

From: Ilya Martynov (ilya@martynov.org)
Date: 11/25/02


From: Ilya Martynov <ilya@martynov.org>
To: Alex Povolotsky <tarkhil@webmail.sub.ru>
Date: Mon, 25 Nov 2002 16:08:11 +0300


>>>>> On Fri, 22 Nov 2002 15:50:27 +0300, Alex Povolotsky <tarkhil@webmail.sub.ru> said:

AP> https cannot be configured with name-based virtual hosts, by
AP> design. jail cannot be configured for more than one IP address,
AP> by design. (don't ask me to wait until jail-ng will be ready)
AP> Jail sits on internal IP, on lo0. fxp0 holds real IP addresses to
AP> be accessed from outside. I'm forwarding incoming connection to
AP> jail, currently with ipnat. I need to pass information about real
AP> (outside) IP to mod_ssl. That is my problem.

AP> plain http works perfectly (name-based virthosts).

AP> I'm using mod_ssl, but not restricted to it.

You can do virtual hosting with https with only one IP. The
trick is using different port numbers for each virtual host.

Outside of jaul you can forward these ports on a set of external IP
using standart port.

-- 
Ilya Martynov,  ilya@iponweb.net
CTO IPonWEB (UK) Ltd
Quality Perl Programming and Unix Support
UK managed @ offshore prices - http://www.iponweb.net
Personal website - http://martynov.org
To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message


Relevant Pages

  • Re: jailed virtual https, anyone?
    ... AJ> What seems to be the problem with the virtual hosts? ... AJ> virtual hosts with https. ... https cannot be configured with name-based virtual hosts, by design. ... jail cannot be configured for more than one IP address, ...
    (FreeBSD-Security)
  • Re: jailed virtual https, anyone?
    ... > AJ> What seems to be the problem with the virtual hosts? ... Google shows nothing relevant on "jail https ... > https cannot be configured with name-based virtual hosts, by design. ... > jail cannot be configured for more than one IP address, ...
    (FreeBSD-Security)
  • Re: ModSSL - Knoppix 3.3
    ... > I create some server key & crt. ... I think you're mixing the virtual hosts too. ... > from REMOTE: ssh ok, http ok, https NOK. ...
    (Focus-Linux)
  • Re: Configuration differences for jails
    ... > As known to all, jail can be used for two purposes, i.e. jailing a single ... > of configuration necessary for setting up a jail? ... it was quite heavy to boot two virtual hosts as described in the jail ... < jeremie at le-hen dot org>< ttz at chchile dot org> ...
    (freebsd-hackers)
  • Re: Mailman + squirrelmail ONLY through https://
    ... i am assuming that you have https up and working. ... I realize the mailman.conf file does not include subsequent ... > AllowOverride None ... > - The http.conf uses virtual hosts for links to specific directories ...
    (Fedora)