IMPLICIT SSL CERTIFICATE MANAGEMENT WITHOUT SERVER NAME INDICATION (SNI)
    22.
    发明申请
    IMPLICIT SSL CERTIFICATE MANAGEMENT WITHOUT SERVER NAME INDICATION (SNI) 有权
    无服务器名称指示(SNI)的隐私SSL证书管理

    公开(公告)号:US20130198511A1

    公开(公告)日:2013-08-01

    申请号:US13359507

    申请日:2012-01-27

    IPC分类号: H04L29/06

    摘要: Embodiments disclose a reverse lookup using an IP:Port-to-hostname table to identify a hostname when only an IP address and port is present in an SSL hello connection, which may occur, for example, when a non-SNI-capable client initiates the SSL hello. Once the hostname is successfully looked up, a naming convention is used to simplify the management and identification of SSL certificates. Different types of SSL certificates are supported. Multiple hostname matches may be associated with a given IP address and port in the IP:Port-to-hostname table. In such case, the first-matching hostname is always used with the naming convention to identify related SSL certificates. The naming convention is applied in such a way that it will first look for the most matching file name to the least matching file name.

    摘要翻译: 实施例公开了使用IP:端口到主机名表的反向查找,以便在SSL hello连接中仅存在IP地址和端口时识别主机名,例如,当非SNI能力的客户端发起时 SSL你好。 一旦主机名成功查找,使用命名约定来简化SSL证书的管理和标识。 支持不同类型的SSL证书。 多个主机名匹配可能与IP:端口到主机名表中的给定IP地址和端口相关联。 在这种情况下,首选匹配的主机名始终与命名约定一起使用,以标识相关的SSL证书。 命名约定以这样一种方式应用,它将首先查找与匹配最少的文件名匹配的最匹配的文件名。