multiple ssl on one ip

18
Hosting multiple SSL Certificates on one IP address

Upload: globalsign

Post on 16-Apr-2017

446 views

Category:

Technology


0 download

TRANSCRIPT

Page 1: Multiple SSL on one IP

Hosting multiple SSL Certificates on one IP address

Page 2: Multiple SSL on one IP

More demand and requirements for SSL

• Google • HTTPS by default on all Google

services• HTTPS Everywhere initiativeLatest: • HTTPS used as a ranking signal• SSL users rewarded• Weight in algorithm set to increase

• PCI compliance• Facebook

Page 3: Multiple SSL on one IP

We are running out of IPv4 addresses

Page 4: Multiple SSL on one IP

How much time is left?

Page 5: Multiple SSL on one IP

Can we use IPv6?

• As long as you select a CA who provides revocation checks (CRL, OCSP) over IPv6.

• But it won’t solve your IPv4 problem!

Page 6: Multiple SSL on one IP

Why do I need a dedicated IP address for SSL?

Page 7: Multiple SSL on one IP

Request on a non-secure connection

Client

• HTTP Request: Can you please send me /contact.html on www.globalsign.com

Server

• HTTP Reply: Here is the content you requested.

Page 8: Multiple SSL on one IP

Request on a secure connection

Client• (TLS Handshake) Hello, I support XYZ Encryption.

Server

• (TLS Handshake) Hi there, here is my public certificate, let’s use this encryption algorithm.

Client• (TLS Handshake) Sounds good to me.

Client

• (Encrypted) HTTP Request: Can you please send me /contact.html on www.globalsign.com

Server• (Encrypted) HTTP Reply: Here is the content you requested.

Page 9: Multiple SSL on one IP

The solution: Server Name Indication

Page 10: Multiple SSL on one IP

Server Name Indication (SNI)

Client

• (TLS Handshake) Hello, I support XYZ Encryption, and I am trying to connect to ’www.globalsign.com'.

Server

• (TLS Handshake) Hi there, here is my public Certificate for www.globalsign.com, and lets use this encryption algorithm.

Client• (TLS Handshake) Sounds good to me.

Client

• (Encrypted) HTTP Request: Can you please send me /contact.html on www.globalsign.com

Server• (Encrypted) HTTP Reply: Here is the content you requested.

Page 11: Multiple SSL on one IP

Applications with no SNI Support

• All versions of Internet Explorer on Windows XP• Android 2.x default browser (other browsers like Opera do

support SNI on Android)• BlackBerry Browser• Windows Mobile up to 6.5

Page 12: Multiple SSL on one IP

Should I use/offer SNI for SSL sites?

• Provide SNI support for free with an SSL Certificate: this will allow each of your customers to have their own individual certificates (with support for higher validation levels, including Extended Validation SSL)

• Combine SNI with a fall back multi domain certificate for users without SNI compatibility - CloudSSL

Page 13: Multiple SSL on one IP

CloudSSL: One certificate, multiple domains

• One SSL Certificate for multiple domain names from different organisations.

• The certificate contains the hosting company’s details.

• Domain control is verified for each domain.

Page 14: Multiple SSL on one IP

SNI combined with CloudSSL

Page 15: Multiple SSL on one IP

With SNI support

Page 16: Multiple SSL on one IP

Windows XP (has no SNI support)

Page 17: Multiple SSL on one IP

Two SSL Certificates for one site!

• No additional costs

• Sites can use all types of certificates (including EV)

• Fully automated provisioning of the legacy CloudSSL Certificate

• No email verification needed

• All domain control checks performed automatically by the program