Skip to content
AITroveRead. Build. Understand.
Make this comfortable

TLS names: verify SNI selection and peer identity independently

Last updated: 1 Oct 20266 min read
tutorial
AdvancedBy AITrove Editorial

SNI helps a server choose a certificate, but it is not proof that the client checked the certificate's Subject Alternative Name. A proxy can route to the right IP and still serve a default certificate, or route to a backend whose certificate names a different service. An IP-level probe, a disabled hostname check, or a test that omits SNI may miss those failures. Define the public host, internal service identity, and upstream TLS name separately when a proxy terminates and re-establishes TLS.

Operational decision

A tax-calculation API moves behind a shared gateway. The edge should present a certificate for the customer-facing host, while the gateway validates its upstream peer against the tax service's internal name. Test both hops with the exact names and trust stores used in production. Send a request with the wrong SNI but a correct HTTP Host header; it must not accidentally reach the tax service under a default certificate. Then send correct SNI with an incorrect Host header and check routing policy. At the backend, replace the certificate with one for an unrelated service in a disposable environment and verify the gateway rejects it even though the signing CA is trusted. Review wildcard scope: a wildcard for one label should not be treated as permission for unrelated deeper names. Include IPv4, IPv6, and standby listeners because they may have different default routes. Record the observed certificate identity and upstream authority in a connection trace without logging private keys or sensitive request bodies. A TLS status code at the edge alone does not show whether the upstream hop validated its peer.

Output
Tax API identity matrix
Edge: requested host, SNI, served SAN, trust anchor
Gateway route: SNI and HTTP authority evaluated separately
Upstream: expected internal name and verified SAN
Negative: correct Host with wrong SNI
Negative: wrong backend cert signed by trusted CA
Variants: IPv4, IPv6, recovery listener

Cost and verification

A two-hop check needs at least two handshakes per path, with O(E × V) tests for E endpoints and V protocol or address variants. TLS termination adds proxy CPU and connection pools, but disabling upstream name checks to save investigation time removes peer authentication. Measure default-certificate hits, upstream verification failures, wrong-route requests, and certificate identity by listener. Re-test after gateway configuration changes, not only after certificate renewal.

Common Mistakes

  • Do not treat SNI selection as client-side hostname validation.
  • Do not disable upstream name checks because the CA is private.
  • Do not test only one address family or the primary listener.

Connected lessons

Practice and check

devops
tls
Storage details