[ietf78-tech] Fwd: Certificates for the IETF

John Kemp kemp at network-services.uoregon.edu
Thu Jul 15 20:02:56 PDT 2010


Appreciate the tips.  I'll give it one last whack tomorrow.

The other obvious alternative here is to generate a self-signed wild-card.
Not sure how people would feel about that, but we could publish the
info on the website for disclosure, and then for Beijing we could use a
real wildcard that was required.

/jgk

On 7/15/2010 7:53 PM, Randy Bush wrote:
>> Apache IP-based virtual hosting doesn't quite make it when the SSL
>> engine is involved.
>>     
> name based does, address suspect not.
>
>   
>> to make this work I would have to run two unique instances of Apache,
>> which would be much uglier than using DNS views.
>>     
> you have not played witht he dns a lot i gather.  :)
>
>   
>> And thank you for your indulgence on this.  I was really hoping we
>> could make this work on the straight and narrow.
>>     
> sorry.
>
> randy
>   



More information about the ietf78-tech mailing list