Return-Path: Delivered-To: apmail-httpd-users-archive@www.apache.org Received: (qmail 270 invoked from network); 29 May 2006 06:26:30 -0000 Received: from hermes.apache.org (HELO mail.apache.org) (209.237.227.199) by minotaur.apache.org with SMTP; 29 May 2006 06:26:30 -0000 Received: (qmail 21038 invoked by uid 500); 29 May 2006 06:26:22 -0000 Delivered-To: apmail-httpd-users-archive@httpd.apache.org Received: (qmail 20273 invoked by uid 500); 29 May 2006 06:26:19 -0000 Mailing-List: contact users-help@httpd.apache.org; run by ezmlm Precedence: bulk Reply-To: users@httpd.apache.org list-help: list-unsubscribe: List-Post: List-Id: Delivered-To: mailing list users@httpd.apache.org Received: (qmail 20262 invoked by uid 99); 29 May 2006 06:26:19 -0000 Received: from asf.osuosl.org (HELO asf.osuosl.org) (140.211.166.49) by apache.org (qpsmtpd/0.29) with ESMTP; Sun, 28 May 2006 23:26:19 -0700 X-ASF-Spam-Status: No, hits=0.0 required=10.0 tests= X-Spam-Check-By: apache.org Received-SPF: pass (asf.osuosl.org: local policy) Received: from [146.109.240.232] (HELO irp0b.swx.com) (146.109.240.232) by apache.org (qpsmtpd/0.29) with ESMTP; Sun, 28 May 2006 23:26:18 -0700 Received: from unknown (HELO gate0a.unix.swx.ch) ([192.168.252.17]) by irp0b.swx.com with ESMTP; 29 May 2006 08:25:56 +0200 X-IronPort-AV: i="4.05,182,1146434400"; d="scan'208"; a="641819:sNHT40867128" Received: from CIWMEXZSA0E.ex.ordersx.org (localhost [127.0.0.1]) by gate0a.unix.swx.ch (8.13.4/8.13.4) with ESMTP id k4T6Pueb023702 for ; Mon, 29 May 2006 08:25:56 +0200 (MEST) Content-Class: urn:content-classes:message MIME-Version: 1.0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.1830 Date: Mon, 29 May 2006 08:25:56 +0200 Message-ID: X-MS-Has-Attach: Importance: normal Priority: normal X-MS-TNEF-Correlator: Thread-Topic: [users@httpd] separate logs for aliases thread-index: AcaC1IH9lP0S1GvySWGiT38FWOFX6wAEpgJg From: "Boyle Owen" To: X-Virus-Checked: Checked by ClamAV on apache.org Subject: RE: [users@httpd] separate logs for aliases X-Spam-Rating: minotaur.apache.org 1.6.2 0/1000/N > -----Original Message----- > From: Om [mailto:omprakash@effigent.net]=20 > Sent: Monday, May 29, 2006 5:53 AM > To: users@httpd.apache.org > Cc: shaibn@gmail.com > Subject: Re: [users@httpd] separate logs for aliases >=20 > Hi Shai, > you can cross check once again in the apache2.2.2 manual. > Check the Virtual hosts section. > I read that. > That configuration is working fine. It depends on how you define "fine"... Your configuration "works" in = that https://site1/ and https://site2/ will both lead to the correct = site and https will be functional. However, if you look carefully, you = will see that both sites are using the same certificate (namely, the = cert from the first VH listed in the config - site1). HTTPS requests to site1 or site2 look identical at the TCP/IP layer = (they're just requests to 192.168.1.3:443 with no HTTP attributes = accessible). Apache finds the first listening VH (which happens to be = site1) and uses the cert from that VH to establish the HTTPS session. = Once the session is open, apache can decrypt the HTTP request and so = then sees the Host header. From then on, it can route the requests to = the appropriate VH so everything *seems* to work. I notice you are using private IPs (192.168.1.3) so maybe this is a LAN = application and you don't really care about authentication. However, in = the real world, this is no solution because you're using the wrong cert = with site2 so have no authentication (your browser should flash an alert = to this effect). In real-world, commercial internet, authentication is every bit as = important as encryption... Rgds, Owen Boyle Disclaimer: Any disclaimer attached to this message may be ignored.=20 > Can you please implement that and check once. >=20 > Thanks, > Om. > Shai wrote: > > On 5/26/06, Brian Rectanus wrote: > >> On 5/26/06, Shai wrote: > >> > But everyone told me that each site needs its own IP or=20 > port to run on > >> > when it comes to SSL.... > >> > >> It does. It is impossible to do name based vhosting w/SSL=20 > because of > >> how SSL works. SSL must negotiate before the HTTP Host=20 > header can be > >> seen. I don't even want to start that argument again ;) > > > > Don't start it, I already knew what I wanted to do. But do you know > > what Om is talking about? > > > > Shai > > > >=20 > --------------------------------------------------------------------- > > The official User-To-User support forum of the Apache HTTP Server=20 > > Project. > > See for more info. > > To unsubscribe, e-mail: users-unsubscribe@httpd.apache.org > > " from the digest: users-digest-unsubscribe@httpd.apache.org > > For additional commands, e-mail: users-help@httpd.apache.org > > > > > > >=20 >=20 > --------------------------------------------------------------------- > The official User-To-User support forum of the Apache HTTP=20 > Server Project. > See for more info. > To unsubscribe, e-mail: users-unsubscribe@httpd.apache.org > " from the digest: users-digest-unsubscribe@httpd.apache.org > For additional commands, e-mail: users-help@httpd.apache.org >=20 Diese E-mail ist eine private und pers=F6nliche Kommunikation. Sie hat = keinen Bezug zur B=F6rsen- bzw. Gesch=E4ftst=E4tigkeit der SWX Gruppe. = This e-mail is of a private and personal nature. It is not related to = the exchange or business activities of the SWX Group. Le pr=E9sent = e-mail est un message priv=E9 et personnel, sans rapport avec = l'activit=E9 boursi=E8re du Groupe SWX. =20 =20 This message is for the named person's use only. It may contain = confidential, proprietary or legally privileged information. No = confidentiality or privilege is waived or lost by any mistransmission. = If you receive this message in error, please notify the sender urgently = and then immediately delete the message and any copies of it from your = system. Please also immediately destroy any hardcopies of the message. = You must not, directly or indirectly, use, disclose, distribute, print, = or copy any part of this message if you are not the intended recipient. = The sender's company reserves the right to monitor all e-mail = communications through their networks. Any views expressed in this = message are those of the individual sender, except where the message = states otherwise and the sender is authorised to state them to be the = views of the sender's company. --------------------------------------------------------------------- The official User-To-User support forum of the Apache HTTP Server Project. See for more info. To unsubscribe, e-mail: users-unsubscribe@httpd.apache.org " from the digest: users-digest-unsubscribe@httpd.apache.org For additional commands, e-mail: users-help@httpd.apache.org