The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

SNI Best Practice

Discussion in 'Security' started by enigmait, Jul 6, 2016.

Tags:
  1. enigmait

    enigmait Registered

    Joined:
    Feb 1, 2012
    Messages:
    1
    Likes Received:
    0
    Trophy Points:
    1
    cPanel Access Level:
    Root Administrator
    Hi,

    Is there a best practice for SNI?

    i.e my main server is hosted on ip 1.1.1.1 (not my real IP) and uses SSL to host the cpanel interfaces.

    Shall I use a separate IP to host all the SNI websites that need certificates i.e 2.2.2.2 or put it all to the primary ip of 1.1.1.1?
     
  2. cPanelMichael

    cPanelMichael Forums Analyst
    Staff Member

    Joined:
    Apr 11, 2011
    Messages:
    30,854
    Likes Received:
    676
    Trophy Points:
    113
    cPanel Access Level:
    Root Administrator
    Hello,

    Here's a brief overview from our SSL FAQ document that explains how SNI support works:

    You can use the same IP address for multiple SSL certificates. The main caveat most people notice with SNI is that SSL becomes accessible for all domain names on the IP address, even if no SSL certificate is installed for the domain name:

    My certificate installed, but visitors who try to securely access other sites on the shared IP address can only see the site with an installed SSL certificate, not my default domain.

    Thank you.
     
Loading...

Share This Page