多域 SSL?

发布于 2024-10-19 00:16:48 字数 155 浏览 11 评论 0 原文

一位同事告诉我,当您通过 SSL 访问网站时,证书不再保证您实际上正在与预期的收件人打交道。这是由于所谓的“多域 SSL 证书”造成的。快速的谷歌搜索似乎表明这些存在 - 但我总是有这样的印象:SSL 提供了加密身份验证。现在不再是这样了吗?这肯定是朝着错误方向迈出的一步吗?

A co-worker told me that when you visit a website over SSL the certificate no longer guarantees that you're actually dealing with the intended recipient. This is due to something called "multi-domain SSL certificates". A quick google search seems to show these exist - but I was always under the impression SSL provided encryption and authentication. Is this no longer the case? Surely this is a step in the wrong direction?

如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。

扫码二维码加入Web技术交流群

发布评论

需要 登录 才能够评论, 你可以免费 注册 一个本站的账号。

评论(3

無處可尋 2024-10-26 00:16:48

有通配符证书,它允许一个域中的所有主机都被同一证书覆盖。颁发它们的成本更高(因为 CA 赚的钱不会像您订购多个单独的单域证书那样多),但是当您需要使用 ssl 覆盖域中的多个主机名时,它可以相当节省。

正确颁发的证书将至少覆盖一个主机名,例如 www.example.com。并且使用通配符,可以覆盖*.example.com。

SSL 本身不保证任何身份识别 - 只是链接被加密。任何证书都可以为您做到这一点 - 即使是自签名的证书。您通过“商业”证书获得的是(理论上)值得信赖的第三方,该第三方表示“我们已验证颁发此 www.example.com 证书的人确实是 www.example.com”

There are wildcard certificates, which allow all hosts in one domain to be covered by the same cert. They're more expensive to get issued (since the CAs wouldn't make as much money as if you'd ordered multiple separate single-domain certs), but when you need to cover multiple hostnames in your domain with ssl, it can be quite a savings.

A properly issued cert will cover at LEAST one host name, like www.example.com. And with wildcarding, can cover *.example.com.

SSL by itself guarantees nothing in the way of identification - simply that the link is encrypted. Any certificate will do that for you - even self-signed ones. What you get with the "commercial" certs is a (theoretically) trustworthy third party saying "we've verified that the person who this www.example.com certificate was issused to really is www.example.com"

知足的幸福 2024-10-26 00:16:48

除了给出的答案之外,我还想补充一些关于 SAN(多域 SSL)的观点。首先,通配符不是多域 ssl,它只保护无限的子域,正如 Marc 已经解释的那样。

要保护多个域,例如:

domain.net
domain.com
mail.domain.com
newdomain.com 

您需要 SAN 证书,起价仅为 60 美元。

In addition to given answer, i would like to add few points about SAN (multidomain SSL). First of all, wildcard is not a multi-domain ssl, it only protects unlimited sub-domains as already explained by Marc.

To protect multiple domains like:

domain.net
domain.com
mail.domain.com
newdomain.com 

you will require SAN certificates that start from just $60.

花想c 2024-10-26 00:16:48

您可以按照文档 使用 ssl 的多域

you can configure multi domain with SSL on both UBUNTU and REDHAT by following the document Multi domian with ssl

~没有更多了~
我们使用 Cookies 和其他技术来定制您的体验包括您的登录状态等。通过阅读我们的 隐私政策 了解更多相关信息。 单击 接受 或继续使用网站,即表示您同意使用 Cookies 和您的相关数据。
原文