- • TLS 1.2 or 1.3 stack on client
- • Edge server hosting multiple certs on one IP
- • Reverse proxy / load balancer SNI routing enabled
- • Input: ClientHello with SNI hostname
- • Output (match): matched X.509 certificate
- • Output (no match): aborted handshake, cert CN mismatch
- • TLS stack (OpenSSL / BoringSSL)
- • Edge proxy (nginx, Envoy, ALB, Cloudflare)
- • Certificate store / SNI dictionary