[Devel] [Users] TLS setup

Juha Heinanen jh at tutpro.com
Fri Oct 7 17:50:48 CEST 2005


since tls connection is setup BEFORE any sip requests are sent, i guess
the proxy (even if it had one certificate per domain) could not know
which server certificate to advertise to the client.  

on the other hand, when proxy is relaying a request, it does know for
which domain it is doing it and thus could use client certificate of
that domain.

what is the conclusion of this?  only generate one server/client
certificate for the proxy even if it serves multiple domains?

-- juha



More information about the Devel mailing list