This is an automated email from the ASF dual-hosted git repository.
markt-asf pushed a commit to branch 10.1.x
in repository https://gitbox.apache.org/repos/asf/tomcat.git
The following commit(s) were added to refs/heads/10.1.x by this push:
new 4cb3350640 Explicitly state virtual host and SNI matching are separate
4cb3350640 is described below
commit 4cb3350640994aa50352818dba146a05d45a70d4
Author: Mark Thomas <[email protected]>
AuthorDate: Wed Sep 30 08:50:51 2026 +0100
Explicitly state virtual host and SNI matching are separate
This has been discussed on the users list for years. It was even
mentioned in the presentation I gave more than 10 years ago when SNI
support was introduced.
---
webapps/docs/changelog.xml | 9 +++++++++
webapps/docs/config/host.xml | 12 ++++++++++++
webapps/docs/config/http.xml | 8 ++++++++
webapps/docs/security-howto.xml | 10 ++++++++++
webapps/docs/ssl-howto.xml | 10 ++++++----
webapps/docs/virtual-hosting-howto.xml | 12 ++++++++++++
6 files changed, 57 insertions(+), 4 deletions(-)
diff --git a/webapps/docs/changelog.xml b/webapps/docs/changelog.xml
index 0ab6416563..5aa7115ca9 100644
--- a/webapps/docs/changelog.xml
+++ b/webapps/docs/changelog.xml
@@ -164,6 +164,15 @@
</fix>
</changelog>
</subsection>
+ <subsection name="Web applications">
+ <changelog>
+ <add>
+ Documentation: Explicitly state that virtual host matching via the HTTP
+ host header and TLS configuration matching via SNI are completely
+ separate processes. (markt)
+ </add>
+ </changelog>
+ </subsection>
<subsection name="Other">
<changelog>
<update>
diff --git a/webapps/docs/config/host.xml b/webapps/docs/config/host.xml
index 42938364ae..3d46e34150 100644
--- a/webapps/docs/config/host.xml
+++ b/webapps/docs/config/host.xml
@@ -516,6 +516,18 @@
</p>
</subsection>
+ <subsection name="Virtual Hosting and TLS">
+
+ <p>Using name-based virtual hosts on a secured connection requires careful
+ configuration of the names specified in a single certificate or the use of
+ SNI. SNI allows multiple certificates with different names to be associated
+ with a single TLS connector. Administrators should be aware that virtual
+ host matching using the HTTP host name header and TLS configuration
+ (including certificate) matching using SNI are completely separate
processes
+ and that it is likely that they will want to keep the two configurations
+ synchronized.</p>
+
+ </subsection>
<subsection name="Lifecycle Listeners">
diff --git a/webapps/docs/config/http.xml b/webapps/docs/config/http.xml
index 2f660a7275..766d2cbffa 100644
--- a/webapps/docs/config/http.xml
+++ b/webapps/docs/config/http.xml
@@ -1205,6 +1205,14 @@
<strong>SSLHostConfig</strong>. For further information, see the SSL Support
section below.</p>
+ <p>Using name-based virtual hosts on a secured connection requires careful
+ configuration of the names specified in a single certificate or the use of
+ SNI. SNI allows multiple certificates with different names to be associated
+ with a single TLS connector. Administrators should be aware that virtual host
+ matching using the HTTP host name header and TLS configuration (including
+ certificate) matching using SNI are completely separate processes and that it
+ is likely that they will want to keep the two configurations
synchronized.</p>
+
<p>When OpenSSL is providing the TLS implementation, one or more
<strong>OpenSSLConfCmd</strong> elements may be nested inside a
<strong>OpenSSLConf</strong> element to configure OpenSSL via OpenSSL's
diff --git a/webapps/docs/security-howto.xml b/webapps/docs/security-howto.xml
index 53556a4bc0..891c38e83d 100644
--- a/webapps/docs/security-howto.xml
+++ b/webapps/docs/security-howto.xml
@@ -398,6 +398,16 @@
increased privileges to the web application. Note that if the security
manager is enabled that the <strong>deployXML</strong> attribute will
default to <code>false</code>.</p>
+
+ <p>Using name-based virtual hosts on a secured connection requires
careful
+ configuration of the names specified in a single certificate or the use
of
+ SNI. SNI allows multiple certificates with different names to be
+ associated with a single TLS connector. Administrators should be aware
+ that virtual host matching using the HTTP host name header and TLS
+ configuration (including certificate) matching using SNI are completely
+ separate processes and that it is likely that they will want to keep the
+ two configurations synchronized.</p>
+
</subsection>
<subsection name="Context">
diff --git a/webapps/docs/ssl-howto.xml b/webapps/docs/ssl-howto.xml
index 4cd3070a32..ffac022d07 100644
--- a/webapps/docs/ssl-howto.xml
+++ b/webapps/docs/ssl-howto.xml
@@ -157,10 +157,12 @@ HSTS header. It allows you to communicate to the browser
that your site should
always be accessed over https.</p>
<p>Using name-based virtual hosts on a secured connection requires careful
-configuration of the names specified in a single certificate or Tomcat 8.5
-onwards where Server Name Indication (SNI) support is available. SNI allows
-multiple certificates with different names to be associated with a single TLS
-connector.</p>
+configuration of the names specified in a single certificate or the use of SNI.
+SNI allows multiple certificates with different names to be associated with a
+single TLS connector. Administrators should be aware that virtual host matching
+using the HTTP host name header and TLS configuration (including certificate)
+matching using SNI are completely separate processes and that it is likely that
+they will want to keep the two configurations synchronized.</p>
</section>
diff --git a/webapps/docs/virtual-hosting-howto.xml
b/webapps/docs/virtual-hosting-howto.xml
index 5f90580225..d35274e28b 100644
--- a/webapps/docs/virtual-hosting-howto.xml
+++ b/webapps/docs/virtual-hosting-howto.xml
@@ -134,6 +134,18 @@ cp localhost/manager.xml stimpy/</source>
host named <code>ren</code>.
</p>
</subsection>
+ <subsection name="Virtual Hosting and TLS">
+ <p>
+ Using name-based virtual hosts on a secured connection requires careful
+ configuration of the names specified in a single certificate or the use
+ of SNI. SNI allows multiple certificates with different names to be
+ associated with a single TLS connector. Administrators should be aware
+ that virtual host matching using the HTTP host name header and TLS
+ configuration (including certificate) matching using SNI are completely
+ separate processes and that it is likely that they will want to keep
the
+ two configurations synchronized.
+ </p>
+ </subsection>
<subsection name="Further Information">
<p>
Consult the configuration documentation for other attributes of the
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]