Simple solution to host multiple HTTPS sites on the same cloud server
brightbox.com
brightbox.com
Basically, putting multiple IPs on cloud servers negates the flexibility of floating IPs. Special configuration on cloud servers should be kept to a minimum imo!
More specifically: IE on XP. IIRC Firefox and Chrome support SNI when running on XP and I would guess Opera does too.
Obviously you would still risk alienating some of your market, but if "try another browser" won't offend that part of your target audience that use XP+IE too much you could consider SNI. Unfortunately if a significant part of your market is corporate users this simply isn't an option and won't be for a while as many of them are locked to XP+IE by their IT setup.
No, SNI is fully broken on all platforms. I tried it for a while, save yourself the headache.
It fails intermittently on all browsers (including latest Firefox and chrome) under various conditions. These failures usually manifest as "Certificate does not match"-warnings for the user.
I have not fully understood all scenarios, but a few seem to be: Keep-alive connection to vhost A, then browser tries connection to vhost B. Loadbalancer doing funny things. Intermediate proxies doing funny things. General implementation bugs (I've seen the cert-warning even on a freshly booted chrome for no obvious reason).
And let's not get started on mobile browers... (hint: the built-in browser may actually seem fine but the http-library in your app still fails intermittently, older androids [widely deployed] have no SNI support at all)
Do yourself a favor and either switch to a wildcard cert or stick with separate IPs.
I'll take your warnings as things to thoroughly test if I ever need to try implement it.
You are right in noting that mobile platforms apparently don't support it well at all.
Really IPv6 is the answer, but for out clients at least that is even more "future magic" then running a decent browser...
If you are writing your REST service with a library that doesn't support SNI then you just fall back to the old one SSL certificate per IP:port. When a browser comes in presenting the SNI option it just gets ignored and life goes on.
This may be the case for Brightbox, but in general a server can differentiate between connections to different IP's. This is how multiple SSL certificates have been supported on one server since forever.
NAT-based floating IP style systems have some great benefits, in particular that the cloud server itself doesn't need to know anything about them. So you can move Cloud IPs between them without changing any configs, or doing anything particularly special on the servers themselves.
Adding multiple IPs to a cloud server adds quite a bit of complexity - makes it harder to just move the floating IPs between servers (because you have to maintain a mapping to each IP, which is different on each server) and it makes configuring the web server more complex too (because the IPs will be different on each server).
In the majority of use cases I've seen, you don't actually need multiple IP addresses on the same cloud server, so it's overkill to support them when port translation can solve the most common problem so neatly.
But we also have some other upcoming features for Cloud IPs that address this in another way :)
http://docs.amazonwebservices.com/ElasticLoadBalancing/lates...