Opened 4 years ago
Closed 2 years ago
#1404 closed Feature Wish ( wontfix )
Client Hello should contain SNI
| Reported by: | davewj100 | Owned by: | |
|---|---|---|---|
| Priority: | major | Milestone: | |
| Component: | Generic / unclassified | Version: | |
| Severity: | Not set (select this one, unless your'e a OpenVPN developer) | Keywords: | sni |
| Cc: | tct |
Description
Good Day, I would really like to see the client TLS handshake specify an SNI (Server Name Indication) in the client hello.
This is a TLS extension which sends a clear-text hostname in handshake, and is very useful for proxying and load balancing.
The SNI should default to the peer's hostname, but a config file option to specify an SNI would also be useful.
Thanks!
Change History (3)
comment:1 Changed 4 years ago by
| Cc: | tct added |
|---|
comment:2 Changed 3 years ago by
comment:3 Changed 2 years ago by
| Resolution: | → wontfix |
|---|---|
| Status: | new → closed |
As has been said by ValdikSS, even if we add SNI, a regular TLS proxy / loadbalancer won't be able to proxy OpenVPN protocol. So the use case is unclear - and if you're not talking to us, there is nothing we can do except "close the ticket".
Reopen if more information can be provided.
OpenVPN does uses TLS internally, but it does not have regular TLS handshake. It encapsulates it into its own protocol. Do you have a proxy or load balancer which supports OpenVPN protocol?