<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: computerdefense.org SSL Fail Image</title>
	<atom:link href="http://www.sslfail.com/2009/01/computerdefense-ssl-fail-image/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.sslfail.com/2009/01/computerdefense-ssl-fail-image/</link>
	<description>1.2.840.113549.1.1</description>
	<lastBuildDate>Thu, 01 Jul 2010 03:13:58 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Michael Dickey</title>
		<link>http://www.sslfail.com/2009/01/computerdefense-ssl-fail-image/comment-page-1/#comment-8</link>
		<dc:creator>Michael Dickey</dc:creator>
		<pubDate>Tue, 13 Jan 2009 21:24:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.sslfail.com/?p=112#comment-8</guid>
		<description>I sort of ask because I know what my answer would be: I can&#039;t. :)

Maybe Apache can twiddle it with vhosts and stuff, but I know my popular load-balancer and IIS both can&#039;t have different SSLs on the same site with two different host headers. At least not without getting crazy complex very quick. You&#039;d probably need to host the site &quot;blah.com&quot; with a real cert named &quot;blah.com&quot; and once the connection is established, http redirect to &quot;www.blah.com:443.&quot;  Or reject the initial SSL attempt and redirect &quot;blah.com:443&quot; to &quot;www.blah.com:443&quot;

Or maybe have two separate virtual hosts/servers that point transparently back to the same site. But the site better be coded to accept that discrepancy! 

All of that is a huge pain to manage.

&quot;www.site.com and site.com are easy pickings for this simple reason.</description>
		<content:encoded><![CDATA[<p>I sort of ask because I know what my answer would be: I can&#8217;t. <img src='http://www.sslfail.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Maybe Apache can twiddle it with vhosts and stuff, but I know my popular load-balancer and IIS both can&#8217;t have different SSLs on the same site with two different host headers. At least not without getting crazy complex very quick. You&#8217;d probably need to host the site &#8220;blah.com&#8221; with a real cert named &#8220;blah.com&#8221; and once the connection is established, http redirect to &#8220;www.blah.com:443.&#8221;  Or reject the initial SSL attempt and redirect &#8220;blah.com:443&#8243; to &#8220;www.blah.com:443&#8243;</p>
<p>Or maybe have two separate virtual hosts/servers that point transparently back to the same site. But the site better be coded to accept that discrepancy! </p>
<p>All of that is a huge pain to manage.</p>
<p>&#8220;www.site.com and site.com are easy pickings for this simple reason.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: romain</title>
		<link>http://www.sslfail.com/2009/01/computerdefense-ssl-fail-image/comment-page-1/#comment-5</link>
		<dc:creator>romain</dc:creator>
		<pubDate>Tue, 13 Jan 2009 18:50:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.sslfail.com/?p=112#comment-5</guid>
		<description>If you are on a shared, I believe you cannot even do that (disable 443)</description>
		<content:encoded><![CDATA[<p>If you are on a shared, I believe you cannot even do that (disable 443)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tyler</title>
		<link>http://www.sslfail.com/2009/01/computerdefense-ssl-fail-image/comment-page-1/#comment-4</link>
		<dc:creator>Tyler</dc:creator>
		<pubDate>Tue, 13 Jan 2009 17:15:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.sslfail.com/?p=112#comment-4</guid>
		<description>Excellent Question :) 

I don&#039;t know that I actually have access to fix that (that particular site exists on shared hosting and not on my server). 

I&#039;m going to investigate though and see if I can either get another SSL Cert, or disable ComputerDefense.org on port 443.</description>
		<content:encoded><![CDATA[<p>Excellent Question <img src='http://www.sslfail.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  </p>
<p>I don&#8217;t know that I actually have access to fix that (that particular site exists on shared hosting and not on my server). </p>
<p>I&#8217;m going to investigate though and see if I can either get another SSL Cert, or disable ComputerDefense.org on port 443.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael Dickey</title>
		<link>http://www.sslfail.com/2009/01/computerdefense-ssl-fail-image/comment-page-1/#comment-3</link>
		<dc:creator>Michael Dickey</dc:creator>
		<pubDate>Tue, 13 Jan 2009 16:13:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.sslfail.com/?p=112#comment-3</guid>
		<description>Just an interesting question: How would you fix that? :)</description>
		<content:encoded><![CDATA[<p>Just an interesting question: How would you fix that? <img src='http://www.sslfail.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
</channel>
</rss>
