Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The relevant RFC says not to send a trailing dot in SNI. Browsers should probably trim the dot out if present. Maybe they aren't doing so because it causes some unexpected compatibility mishap, maybe in reality it rarely causes any trouble so nobody got around to it.


https://tools.ietf.org/html/rfc3546#section-3.1

> "HostName" contains the fully qualified DNS hostname of the server, as understood by the client. The hostname is represented as a byte string using UTF-8 encoding, without a trailing dot.


I was not aware of this!




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: