Hacker News new | ask | show | jobs
by mrweasel 4705 days ago
Older Win XP machines doesn't support SNI, so you could get around it with an older machine. Of cause that's a problem that will go away over time.
1 comments

To connect to an HTTPS site without SNI, the IP can only host a single domain, so they can just block the whole (IP:443) combination without affecting any other site.
What if the IP is dynamic? Say an Azure Cloud Service.
I think the problem is that you'd need a different X.509 certificate for TLS, for each and every single IP.
The certificate is issued for the domain, not the IP.