[squid-users] Multiple SSL certificates on same IP

Alex Rousskov rousskov at measurement-factory.com
Thu Dec 20 16:26:35 UTC 2018


On 12/20/18 5:45 AM, Bruno de Paula Larini wrote:
> why Squid would have problems with SNI and
> OpenSSL when other webservers/proxies have this feature using
> OpenSSL/LibreSSL libs?

Squid lacks the necessary code to support SNI in accelerator mode when
using OpenSSL.


> Why SNI would be such a big deal?

SNI support with OpenSSL is not a "big deal"[1]. Apparently, nobody has
needed that support badly enough to either add that support or sponsor
that addition.

[1]
https://stackoverflow.com/questions/5113333/how-to-implement-server-name-indication-sni

Alex.


More information about the squid-users mailing list