Martin Helie wrote:

> I seem to have read something about apache and modssl not being too friendly
> towards name based virtual hosts, but was wondering if anyone had more
> info...

It's not specifically apache and modssl, but also other webserver
software as well.

The trouble is the way name based virtual hosts work - a connection is
made, then the Host: header is used to determine which site you are
talking about. When you make an SSL connection, the decision on whether
the connection should be allowed or not is done when the connection is
made. At this point, the webserver does not know yet what server you are
trying to access, and so cannot make a proper decision on whether the
connection should proceed or not.

> So far, I have been able to allow _one_ virtual host to access port 443, but
> if I enable SSL for any other vhosts, things get kind of weird.
> 
> Are my only options to get IP addresses for each host, or run multiple
> instances of httpd configured differently? Any other ideas?

Use one IP address for each host. There is no need to run multiple httpd
daemons, just one installation can serve multiple secure hosts and
multiple Ip addresses.

Regards,
Graham
--
______________________________________________________________________
Apache Interface to OpenSSL (mod_ssl)                   www.modssl.org
User Support Mailing List                      [EMAIL PROTECTED]
Automated List Manager                            [EMAIL PROTECTED]

Reply via email to