Re: HTTPS and URL encoding

dap99_at_i-55.com
Date: 05/28/04


Date: Thu, 27 May 2004 22:59:52 -0500

On Thu, 27 May 2004 18:36:23 -0400, Barry Margolin
<barmar@alum.mit.edu> wrote:

>In article <40B66A5F.F403FFB1@anta.net>, Thor Kottelin <thor@anta.net>
>wrote:
>> > Not if it's a virtual server -- multiple names map to the same address,
>> > and the reverse lookup probably wouldn't produce the one that the user
>> > used.
>>
>> It's not very common for HTTPS to be available on name-based virtual hosts,
>> is it?
>
>Good point. Now that you remind me, I think there's a problem with
>certificate verification, which is based on IP rather than name.

I wish they would fix that. Yes, it would be painful and a long
process, but I can still wish. Having to dedicate an IP for each SSL
site is a real administrative pain. You can host multiple SSL sites on
one IP using different ports, but users get scared when they click to
https://ssl.site.com:534.