Skip to content

HTTPS Feature request: Hotswap TLS certificates #10349

Description

@fresheneesz

I'd like to suggest that there be a way to swap out your TLS certificate (and TLS keys would be nice as well) without bringing your server down. This would enable me to properly do fully-automatic certificate renewal with something like Lets' Encrypt. Existing connections could keep using the old cert, but new connections would use the new one. Should be possible, right?

Activity

  1. added
    feature requestIssues requesting new Node.js features.
    tlsIssues and PRs related to the tls subsystem.
    on Dec 20, 2016
  2. mscdex commented on Dec 20, 2016

    @mscdex
    Contributor

    Isn't this already possible via SNICallback?

  3. fresheneesz commented on Dec 20, 2016

    @fresheneesz
    Author

    Ooo, looks like it is.. I'll have to try that.

  4. sam-github commented on Dec 20, 2016

    @sam-github
    Contributor

    The docs say the SNICallback is only used if the client uses the SNI extension. Is that wrong? Will the SNICallback be used for every TLS handshake if defined?

  5. mscdex commented on Dec 20, 2016

    @mscdex
    Contributor

    @sam-github Not wrong, but almost all modern clients are SNI-capable. There is an example supported client table here FWIW.

  6. addaleax commented on Dec 20, 2016

    @addaleax
    Member

    See also #4464 (which makes sound like a duplicate of that?)

  7. bnoordhuis commented on Apr 26, 2017

    @bnoordhuis
    Member

    Closing as duplicate of #4464.

  8. added
    duplicateIssues and PRs that are duplicates of other issues or PRs.
    on Apr 26, 2017
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    duplicateIssues and PRs that are duplicates of other issues or PRs.feature requestIssues requesting new Node.js features.tlsIssues and PRs related to the tls subsystem.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions