#1404 closed Feature Wish ( wontfix )

Client Hello should contain SNI

Reported by: davewj100 Owned by:
Priority: major Milestone:
Component: Generic / unclassified Version:
Severity: Not set (select this one, unless your'e a OpenVPN developer) Keywords: sni
Cc: tct

Description

Good Day, I would really like to see the client TLS handshake specify an SNI (Server Name Indication) in the client hello.

This is a TLS extension which sends a clear-text hostname in handshake, and is very useful for proxying and load balancing.

The SNI should default to the peer's hostname, but a config file option to specify an SNI would also be useful.

Thanks!

Change History (3)

comment:1 Changed 4 years ago by tct

Cc: tct added

comment:2 Changed 3 years ago by ValdikSS

OpenVPN does uses TLS internally, but it does not have regular TLS handshake. It encapsulates it into its own protocol. Do you have a proxy or load balancer which supports OpenVPN protocol?

comment:3 Changed 2 years ago by Gert Döring

Resolution: → wontfix
Status: new → closed

As has been said by ValdikSS, even if we add SNI, a regular TLS proxy / loadbalancer won't be able to proxy OpenVPN protocol. So the use case is unclear - and if you're not talking to us, there is nothing we can do except "close the ticket".

Reopen if more information can be provided.