Monday, April 30, 2018

Missing SNI in Client Hello

Hey

So I'm having an issue with an application running on Win2k8 R2 not having the Server Name extension and thus SNI missing from the Client Hello's. Therefore when trying to match via FireSIGHT there's no URL data and it blocks.

However we can successfully connect from the server using a web browser (IE, Chrome) and the SNI is present when attempted there.

Aside from contacting the vendor of the application to inquire, is there anything else server side I could be looking at here?



No comments:

Post a Comment