This is an automated email from the ASF dual-hosted git repository.

markt-asf pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/tomcat.git


The following commit(s) were added to refs/heads/main by this push:
     new c2b1c9dab0 Explicitly state virtual host and SNI matching are separate
c2b1c9dab0 is described below

commit c2b1c9dab0371cec6d5c2ee49105dd7f4b294da3
Author: Mark Thomas <[email protected]>
AuthorDate: Wed Sep 30 08:50:51 2026 +0100

    Explicitly state virtual host and SNI matching are separate
    
    This has been discussed on the users list for years. It was even
    mentioned in the presentation I gave more than 10 years ago when SNI
    support was introduced.
---
 webapps/docs/changelog.xml             |  5 +++++
 webapps/docs/config/host.xml           | 12 ++++++++++++
 webapps/docs/config/http.xml           |  8 ++++++++
 webapps/docs/security-howto.xml        | 10 ++++++++++
 webapps/docs/ssl-howto.xml             | 10 ++++++----
 webapps/docs/virtual-hosting-howto.xml | 12 ++++++++++++
 6 files changed, 53 insertions(+), 4 deletions(-)

diff --git a/webapps/docs/changelog.xml b/webapps/docs/changelog.xml
index 7caeb4bdb0..8acc3525b2 100644
--- a/webapps/docs/changelog.xml
+++ b/webapps/docs/changelog.xml
@@ -432,6 +432,11 @@
         Tapestry attributes, used for locale session sorting. (remm)
       </update>
       <!-- Entries for backport and removal before 12.0.0-M1 below this line 
-->
+      <add>
+        Documentation: Explicitly state that virtual host matching via the HTTP
+        host header and TLS configuration matching via SNI are completely
+        separate processes. (markt)
+      </add>
     </changelog>
   </subsection>
   <subsection name="jdbc-pool">
diff --git a/webapps/docs/config/host.xml b/webapps/docs/config/host.xml
index 9175283254..080b373eac 100644
--- a/webapps/docs/config/host.xml
+++ b/webapps/docs/config/host.xml
@@ -509,6 +509,18 @@
     </p>
   </subsection>
 
+  <subsection name="Virtual Hosting and TLS">
+
+    <p>Using name-based virtual hosts on a secured connection requires careful
+    configuration of the names specified in a single certificate or the use of
+    SNI. SNI allows multiple certificates with different names to be associated
+    with a single TLS connector. Administrators should be aware that virtual
+    host matching using the HTTP host name header and TLS configuration
+    (including certificate) matching using SNI are completely separate 
processes
+    and that it is likely that they will want to keep the two configurations
+    synchronized.</p>
+
+  </subsection>
 
   <subsection name="Lifecycle Listeners">
 
diff --git a/webapps/docs/config/http.xml b/webapps/docs/config/http.xml
index 434d35aadc..d22e33c15b 100644
--- a/webapps/docs/config/http.xml
+++ b/webapps/docs/config/http.xml
@@ -1121,6 +1121,14 @@
   <strong>SSLHostConfig</strong>. For further information, see the SSL Support
   section below.</p>
 
+  <p>Using name-based virtual hosts on a secured connection requires careful
+  configuration of the names specified in a single certificate or the use of
+  SNI. SNI allows multiple certificates with different names to be associated
+  with a single TLS connector. Administrators should be aware that virtual host
+  matching using the HTTP host name header and TLS configuration (including
+  certificate) matching using SNI are completely separate processes and that it
+  is likely that they will want to keep the two configurations 
synchronized.</p>
+
   <p>When OpenSSL is providing the TLS implementation, one or more
   <strong>OpenSSLConfCmd</strong> elements may be nested inside a
   <strong>OpenSSLConf</strong> element to configure OpenSSL via OpenSSL's
diff --git a/webapps/docs/security-howto.xml b/webapps/docs/security-howto.xml
index ec8e5039b9..51a2bd38dc 100644
--- a/webapps/docs/security-howto.xml
+++ b/webapps/docs/security-howto.xml
@@ -368,6 +368,16 @@
       increased privileges to the web application. Note that if the security
       manager is enabled that the <strong>deployXML</strong> attribute will
       default to <code>false</code>.</p>
+
+      <p>Using name-based virtual hosts on a secured connection requires 
careful
+      configuration of the names specified in a single certificate or the use 
of
+      SNI. SNI allows multiple certificates with different names to be
+      associated with a single TLS connector. Administrators should be aware
+      that virtual host matching using the HTTP host name header and TLS
+      configuration (including certificate) matching using SNI are completely
+      separate processes and that it is likely that they will want to keep the
+      two configurations synchronized.</p>
+
     </subsection>
 
     <subsection name="Context">
diff --git a/webapps/docs/ssl-howto.xml b/webapps/docs/ssl-howto.xml
index 626b475b66..8eee9f1210 100644
--- a/webapps/docs/ssl-howto.xml
+++ b/webapps/docs/ssl-howto.xml
@@ -157,10 +157,12 @@ HSTS header. It allows you to communicate to the browser 
that your site should
 always be accessed over https.</p>
 
 <p>Using name-based virtual hosts on a secured connection requires careful
-configuration of the names specified in a single certificate or Tomcat 8.5
-onwards where Server Name Indication (SNI) support is available. SNI allows
-multiple certificates with different names to be associated with a single TLS
-connector.</p>
+configuration of the names specified in a single certificate or the use of SNI.
+SNI allows multiple certificates with different names to be associated with a
+single TLS connector. Administrators should be aware that virtual host matching
+using the HTTP host name header and TLS configuration (including certificate)
+matching using SNI are completely separate processes and that it is likely that
+they will want to keep the two configurations synchronized.</p>
 
 </section>
 
diff --git a/webapps/docs/virtual-hosting-howto.xml 
b/webapps/docs/virtual-hosting-howto.xml
index 5f90580225..d35274e28b 100644
--- a/webapps/docs/virtual-hosting-howto.xml
+++ b/webapps/docs/virtual-hosting-howto.xml
@@ -134,6 +134,18 @@ cp localhost/manager.xml stimpy/</source>
         host named <code>ren</code>.
       </p>
     </subsection>
+    <subsection name="Virtual Hosting and TLS">
+      <p>
+        Using name-based virtual hosts on a secured connection requires careful
+        configuration of the names specified in a single certificate or the use
+        of SNI. SNI allows multiple certificates with different names to be
+        associated with a single TLS connector. Administrators should be aware
+        that virtual host matching using the HTTP host name header and TLS
+        configuration (including certificate) matching using SNI are completely
+        separate processes and that it is likely that they will want to keep 
the
+        two configurations synchronized.
+      </p>
+    </subsection>
     <subsection name="Further Information">
       <p>
         Consult the configuration documentation for other attributes of the


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to