[Cialug] Is it OK to use SNI?

Pixie pix at kepibu.org
Sun Nov 11 23:00:16 CST 2012


On 2012.11.11 22:14, Matthew Nuzum wrote:
> Have we gotten to the point where it's safe to use SNI now?

That depends on your visitors and what percentage you're willing to give 
a substandard experience.  Check your stats to see how many are using 
browser/OS combinations which don't handle SNI.

My stats, for instance, say ~6% IE6/7 on one site (definitely no SNI), 
and ~11% IE8 (possibly SNI, depending on OS and service pack), both of 
which are far too large for my tastes.


> Besides that, one thing that's not clear to me is if the process for
> getting a cert changed. Is it diff now if using SNI?

SNI only affects the TLS handshake.  It is irrelevant to the actual 
certificates.


-- 


More information about the Cialug mailing list