Howto: Multi-domain SSL, Nginx, 1 IP address
playnice.ly
playnice.ly
This is a plain lie. This article just describes a technology that has been available for years: using Subject Alternative Names to declare all the host names in a single X.509 certificate. As far as I can tell, real CAs have been signing these types of certs for years (one random example: https://www.rapid7.com is valid for "www.rapid7.com" and "rapid7.com" without using a wildcard cert). The article call these certs "UCC SSL certs" but it is nothing more than a marketing name to sell Subject Alternative Names.
lie, noun, an intentionally false statement.
To insinuate that someone is a liar used to be a considerable personal slight and writing it here makes it libelous. Have you proven intention? Would it not be more polite to say that the OP was simply mistaken. I would kindly ask the OP to rewrite the offending sentence, perhaps like so "In the past it has been difficult to serve SSL requests for multiple domains from the same IP address."
That this comment has received a number of up votes is disconcerting. Where is the decorum oft afforded the HN community?
1. http://www.google.com/search?q=ssl+cert
2. Click on one of the GoDaddy ads.
3. ???
4. Save
The key part was the "1 ip address"
I read that Microsoft added the StartCom CA to Windows in 2009. So I would assume that people browsing the web with ancient, unpatched versions of IE will have problems. How big a deal that is probably depends on your site.
The problems with SNI have already been discussed here, but we've also found issues with older Android browsers getting certificate warnings when using UC certificates. Specifically, there are issues when using a wildcard UC certificate (so one can have both https://root.tld and https://anyvar.root.tld) on Android OS's prior to 2.0.
Also, if you use StartSSL, be sure to configure the intermediate CA (in addition to a root CA) in your server's config. Again, this was an issue where most desktop browsers worked fine, but a handful of mobile browsers failed or had extended load times.
https://www.cacert.org/ also lets you generate certificates for multiple domains using subjectAltName. My website at https://secure.grepular.com/ has a CN of ".cardwellit.com", but then has three values in subjectAltName, "cardwellit.com", "grepular.com" and "*.grepular.com"
Edit: or maybe not.
ERROR: certificate common name `*.github.com' doesn't match requested host name `github.com'.
If your domain list is quite static/stable, this is great.
Otherwise, as I believe it still suffers from the problem that you must create a new UCC cert ($$++) each time you want to add to the domain list, I'd be happier with SNI and one cert per domain. ($$--).
http://www.crsr.net/Notes/Apache-HTTPS-virtual-host.html
It does cover the Apache config towards the end, and it doesn't look too involved. You can still follow the OP up until just before the "Chained certificates" section.
If you do need to use a chained certificate in Apache, you should see:
http://httpd.apache.org/docs/2.0/mod/mod_ssl.html#sslcertifi...
I hope that helps!
Obviously, SNI is the superior solution for a shared hosting environment. The approach described in the article is fine for consolidating some related domains into one certificate, but would be an expensive management headache for many unrelated domains.
That's what I get for not reading the whole thing, sorry.