Re: SNI vs Host: and a trailing dot

On 17/03/2016 1:09 a.m., Michael Sweet wrote:
> FWIW, CUPS has traditionally stripped the trailing dot from both since most printers (and web sites, for that matter) have difficulty handling "example.com."
> 


FWIW; Squid likewise does that as well.

IIRC we determined that the trailing dot syntax was an outcome of people
partially understanding the DNS specifications. Those DNS specs talk
about using the trailing dot to terminate the domain labels. But on
close inspection it is only supposed to be used in the wire-format for
DNS packets. Intermediate representations like HTTP messages or TLS SNI
are expected to have no trailing dot for valid FQDN.

Amos

Received on Wednesday, 16 March 2016 12:45:07 UTC