[TLS] ALPN or NPN ?

ALPN and NPN seem very close. Nevertheless they impact differently the performance and the complexity of migration scenario.

 

More and more applications are being migrated over TLS. Consequently reverse proxies have to deal with more and more complex situations and need to know the application protocol to guide incoming TLS sessions toward the right servers. ALPN is very efficient because with ALPN a reverse proxy is able to start the resource selection immediately after the processing of the ClientHello. NPN is less efficient as the reverse proxy has to wait an additional TLS exchange before initiating the resource.

 

More and more applications are being partially or totally virtualized and carried over TLS. In these cases reverse proxies rely on information like Server Name Indication to select the server credential to return in the ServerHello. There are situations where the selection of the server credential requires the knowledge of the Server Name and of the Application Protocol. ALPN and SNI provide this information in time as there are both carried in the ClientHello. This is not possible with NPN as the Application Protocol is determined by the client after receiving the ServerHello.

 

源 : http://www.ietf.org/mail-archive/web/tls/current/msg09272.html

posted on   --LP--  阅读(224)  评论(0编辑  收藏  举报

(评论功能已被禁用)
编辑推荐:
· 如何编写易于单元测试的代码
· 10年+ .NET Coder 心语,封装的思维:从隐藏、稳定开始理解其本质意义
· .NET Core 中如何实现缓存的预热?
· 从 HTTP 原因短语缺失研究 HTTP/2 和 HTTP/3 的设计差异
· AI与.NET技术实操系列:向量存储与相似性搜索在 .NET 中的实现
阅读排行:
· 地球OL攻略 —— 某应届生求职总结
· 周边上新:园子的第一款马克杯温暖上架
· Open-Sora 2.0 重磅开源!
· 提示词工程——AI应用必不可少的技术
· .NET周刊【3月第1期 2025-03-02】
< 2025年3月 >
23 24 25 26 27 28 1
2 3 4 5 6 7 8
9 10 11 12 13 14 15
16 17 18 19 20 21 22
23 24 25 26 27 28 29
30 31 1 2 3 4 5

导航

统计

点击右上角即可分享
微信分享提示