{"id":5389,"date":"2017-11-17T12:26:15","date_gmt":"2017-11-17T17:26:15","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=5389"},"modified":"2020-08-24T15:40:40","modified_gmt":"2020-08-24T19:40:40","slug":"what-is-sni","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/what-is-sni\/","title":{"rendered":"What is Server Name Indication (SNI)?"},"content":{"rendered":"<h2>SNI: Running multiple SSL certificates on the same IP Address<\/h2>\n<p>What is SNI? Server Name Indication is a crucial component of SSL that oftentimes goes under the radar. SNI is what allows multiple websites to exist on the same IP address. Without SNI, each hostname would require its own IP address in order for an SSL certificate to be installed. However, SNI solves this problem.<\/p>\n<p>Now, what does all that mean?<\/p>\n<p>Let\u2019s Hash it Out.<span id=\"newline\"><\/span><\/p>\n<h2>Why Name-Based Hosts Don\u2019t Work Well with SSL<\/h2>\n<p>Back in the olden days, which in internet years means 2007, you would solve the issue of multiple websites being hosted on same IP address with name-based hosts. Basically, when a client requests a particular website, it uses a unique HTTP header that includes the intended hostname. In response, the server matches this header to the intended website and transports the user there.<\/p>\n<p>Where this breaks down is when HTTPS enters the picture. That\u2019s because SSL requires an SSL handshake before an encrypted connection can be made between a client and a server. The HTTP header that contained the intended hostname wouldn\u2019t be downloaded until after the handshake has been completed, which means that the server wouldn\u2019t know which website to make the connection to.<\/p>\n<span style=\"--tl-form-height-m:150.25px;--tl-form-height-t:121.4583px;--tl-form-height-d:121.4583px;\" class=\"tl-placeholder-f-type-shortcode_12753 tl-preload-form\"><span><\/span><\/span>\n<h2>What is SNI?<\/h2>\n<p>Server Name Indication is an extension to the SSL\/TLS protocol that allows multiple SSL certificates to be hosted on a single IP address. The way SNI does this is by inserting the HTTP header into the SSL handshake. Because the server can see the intended hostname during the handshake, it can connect the client to the requested website.<\/p>\n<p>Before Server Name Indication was created, each website that you wanted to encrypt had to have a unique IP address. This proved incredibly costly. It also had the unintended side effect of rapidly consuming IPv4 IP addresses.<\/p>\n<p>Let\u2019s not go too far into the weeds here, but there are a finite number of IP addresses. IPv4 or Internet Protocol version 4, assigns addresses to each device participating in a computer network that uses the Internet Protocol for communication. An IPv4 IP address looks like this:<\/p>\n<pre><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-5391\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/11\/ipv4-100629207-orig.png\" alt=\"what is sni?\" width=\"774\" height=\"456\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/11\/ipv4-100629207-orig.png 774w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/11\/ipv4-100629207-orig-300x177.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/11\/ipv4-100629207-orig-768x452.png 768w\" sizes=\"auto, (max-width: 774px) 100vw, 774px\" \/><\/pre>\n<p>There are only around 4 billion IPv4 IP addresses. Eventually, all 4 billion+ addresses WILL be depleted. But before SNI, they were going a lot faster. Server Name Indication helped to stave off that eventual depletion a little longer.<\/p>\n<p>Eventually, the internet will migrate to IPv6 IP addresses. There are potentially 340 undecillion IPv6 addresses\u2014so that list should last a little longer.<\/p>\n<h2>What does the future hold for SNI?<\/h2>\n<p>The biggest concern over SNI was its scalability. At the outset, some believed that web browsers and servers wouldn\u2019t adopt the technology fast enough. That concern proved to be largely unfounded though. Today, <a href=\"https:\/\/blogs.akamai.com\/2017\/03\/reaching-toward-universal-tls-sni.html\" rel=\"nofollow\">according to Akamai<\/a>, almost 98% of the clients requesting an HTTPS-enabled site support SNI.<\/p>\n<p><em><strong>RELATED:<\/strong> <a href=\"https:\/\/www.thesslstore.com\/blog\/what-is-hypertext-strict-transport-security-hsts\/\">What is HSTS?<\/a><\/em><\/p>\n<h2>What we Hashed Out (for skimmers)<\/h2>\n<p>Here\u2019s what we covered in today\u2019s discussion:<\/p>\n<ul>\n<li>What is SNI? Server Name Indication allows multiple SSL certificates to be hosted on a single IP address<\/li>\n<li>SNI inserts the HTTP header into the SSL handshake to inform the server which website to connect to<\/li>\n<li>Today, 98% of clients requesting HTTPS support SNI<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>SNI: Running multiple SSL certificates on the same IP Address What is SNI? Server Name Indication is a crucial component of SSL that oftentimes goes under the radar. SNI is&#8230;<\/p>\n","protected":false},"author":6,"featured_media":5390,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[130],"tags":[2364],"class_list":["post-5389","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-everything-encryption","tag-sni","post-with-tags"],"views":49135,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/11\/iStock-871467860.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/5389","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=5389"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/5389\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/5390"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=5389"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=5389"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=5389"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}