⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 998+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
Staff SRE / Principal Architect [L3] Networking Staff SRE Scenario [L3]

Q: Your company hosts 100 different HTTPS websites (e.g., `clientA.com`, `clientB.com`) entirely behind a single Application Load Balancer with one single IP address. How does the ALB know which SSL/TLS certificate to present to the user during the highly cryptographic TCP handshake, before any HTTP headers are sent?

In the early days of the internet, this was impossible—each HTTPS domain required its own dedicated IP address because the server didn't ...

#Networking #Networking #L3 #VPC #DNS #Security
🎙️ Candidate Opening & Architectural Context
""In our multi-VPC setup, services in private subnets ran into this exact routing obstacle. The interviewer is testing: Server Name Indication (SNI), TLS handshake internals.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement

🛠️ Production Runbook & Step-by-Step Resolution

1️⃣

Production Solution & Architecture

In the early days of the internet, this was impossible—each HTTPS domain required its own dedicated IP address because the server didn't know which website the client wanted until *after* the TLS encryption was established, but it needed to provide the right certificate *to* establish it. This is solved by SNI (Server Name Indication). SNI is an extension to the TLS protocol. During the very first step of the TLS handshake (the ClientHello packet), the user's browser transmits the requested hostname (clientA.com) in plaintext before encryption begins. The ALB reads this plaintext SNI extension, instantly searches its certificate store, selects the correct certificate for clientA.com, and completes the secure handshake.

💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: In the early days of the internet, this was impossible—each HTTPS domain required its own dedicated IP address because the server ."
⚡ 60-Second Elevator Pitch Talking Points
  • Immediate Triage: In the early days of the internet, this was impossible—each HTTPS domain required its own dedic
  • Run targeted verification commands before modifying configuration.
  • Automate permanent guardrails (CI check, alerts, IaC policy) to prevent recurrence.
Advertisement
Want more Networking scenarios?
Explore our complete collection of scenario-based Networking interview runbooks.
Browse All Networking Questions →

📚 Related Production Scenarios in Networking