[Swan] Intermittent download.libreswan.org certificate hostname mismatch

Tuomo Soini tis at foobar.fi
Sun Apr 23 18:00:49 UTC 2017


On Sun, 23 Apr 2017 10:43:25 -0400
Daniel McCarney <daniel at binaryparadox.net> wrote:

> This seems like the wrong take-away. I agree that SNI support is 
> important, but I'd also expect if the project decides to take this 
> hard-line stance on SNI client support that it be done consistently
> so 100% of requests without SNI fail.

No. We go without SNI requirement as far as we can. There are several
systems in our infrastructure and there is no simple way to go without
SNI requirement on Finland server. This is result of careful planning,
not just random configuration.

-- 
Tuomo Soini <tis at foobar.fi>
Foobar Linux services
+358 40 5240030
Foobar Oy <http://foobar.fi/>


More information about the Swan mailing list