Date: Thu, 28 Jul 2005 15:39:27 +0200 From: Uzi Klein <uzi@bmby.com> To: freebsd-stable@FreeBSD.ORG Subject: Re: Apache2 just listening to https? Message-ID: <42E8E00F.6060103@bmby.com> In-Reply-To: <200507281217.j6SCHiNC048246@lurza.secnetix.de> References: <200507281217.j6SCHiNC048246@lurza.secnetix.de>
next in thread | previous in thread | raw e-mail | index | archive | help
[-- Attachment #1 --] Oliver Fromme wrote: > Uzi Klein <uzi@bmby.com> wrote: > > Oliver Fromme wrote: > > > Uzi Klein <uzi@bmby.com> wrote: > > > > Actually, SSL can not be configured per name vhost. (or at least can not > > > > work) > > > > Because SSL handshake is used before http headers, it just can't be done. > > > > > > You can configure SSL perfectly fine per virtual host, > > > provided that they have separate addresses. You can > > > even use SSL for virtual hosts that share an address, > > > if they listen on different ports (in this case you > > > can use redirects for convenience, so users don't have > > > to type the port numbers). > > > > > > It's correct that SSL doesn't work for pure name-based > > > virtual hosts (not using "special tricks"), but nobody > > > was talking about that. > > > > > > > note the *name vhost* > > Only _you_ were talking about named virtual hosts. :-) > They are not an issue in this case. > > > and the user's conf. > The original post has > <VirtualHost *:80> > ServerName freebsd.domain.net > ServerAlias freebsd.domain.net > DocumentRoot /usr/local/www/data > </VirtualHost> > > ...which should be loaded on startup. Also, i activated > > NameVirtualHost *:80 But it's really getting off topic. looks like the problem has to do with DocumentRoot or DirectoryIndex in httpd.conf. > The user's configuration, as far as it has been (partially) > shown, contains just two virtual hosts which run on different > ports (port 80 for for HTTP and port 443 for HTTPS). > So name-based virtual hosts are _not_ an issue here. > > Name-based virtual hosts would be a problem if you run > multiple of them on the same IP address _and_ on the same > port with SSL (usually 443). That's not the case here. > > Best regards > Oliver > -- Uzi Klein Software Development Executive B.M.B.Y Software Systems LTD. Phone: 972-4-9597989 Fax: 972-3-6179336 Email: uzi@bmby.com http://www.bmby.com [-- Attachment #2 --] 0 *H 010 + 0 *H 0A00 *H 0b10 UZA1%0#U Thawte Consulting (Pty) Ltd.1,0*U#Thawte Personal Freemail Issuing CA0 050705150547Z 060705150547Z0>10UThawte Freemail Member10 *H uzi@bmby.com00 *H 0 p|GNo(F 4 PH w͙<6ukZKDf pl(߾)&ա@0ň/ݿܮd*tD!`[}/Pl G, )0'0U0uzi@bmby.com0U0 0 *H OTZĎB>oSKƼH/BU!/wݖK)) aAj"{7"H dq ş\!hAM{Լ+X7ŦSMi|k[;W0A00 *H 0b10 UZA1%0#U Thawte Consulting (Pty) Ltd.1,0*U#Thawte Personal Freemail Issuing CA0 050705150547Z 060705150547Z0>10UThawte Freemail Member10 *H uzi@bmby.com00 *H 0 p|GNo(F 4 PH w͙<6ukZKDf pl(߾)&ա@0ň/ݿܮd*tD!`[}/Pl G, )0'0U0uzi@bmby.com0U0 0 *H OTZĎB>oSKƼH/BU!/wݖK)) aAj"{7"H dq ş\!hAM{Լ+X7ŦSMi|k[;W0?0 0 *H 010 UZA10UWestern Cape10U Cape Town10U Thawte Consulting1(0&UCertification Services Division1$0"UThawte Personal Freemail CA1+0) *H personal-freemail@thawte.com0 030717000000Z 130716235959Z0b10 UZA1%0#U Thawte Consulting (Pty) Ltd.1,0*U#Thawte Personal Freemail Issuing CA00 *H 0 Ħ<UsUNʙZhup[v:aQP 0cZ,p+Z?qV˯<6$*+w=+>@dקe*TH<a@dr` 00U0 0CU<0:08642http://crl.thawte.com/ThawtePersonalFreemailCA.crl0U0)U"0 010UPrivateLabel2-1380 *H HP. fgCL!6-6/P p<ab:~ t%Pb'qW%ݩ9 Oe_N4[5MwV!x!5$F]_eO100i0b10 UZA1%0#U Thawte Consulting (Pty) Ltd.1,0*U#Thawte Personal Freemail Issuing CA0 + 0 *H 1 *H 0 *H 1 050728133927Z0# *H 1KbUEޮYx0R *H 1E0C0 *H 0*H 0 *H @0+0 *H (0x +71k0i0b10 UZA1%0#U Thawte Consulting (Pty) Ltd.1,0*U#Thawte Personal Freemail Issuing CA0z*H 1ki0b10 UZA1%0#U Thawte Consulting (Pty) Ltd.1,0*U#Thawte Personal Freemail Issuing CA0 *H #:Bro\ $QޡB\%CK~le~&էCmaM7kB *DYGrYex7ncɄ=ϽٮJbbk!ifZskg`aZJ
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?42E8E00F.6060103>
