Q: Your company hosts 100 different HTTPS websites (e.g., `clientA.com`, `clientB.com`) entirely behind a single Application Load Balancer with one single IP address. How does the ALB know which SSL/TLS certificate to present to the user during the highly cryptographic TCP handshake, before any HTTP headers are sent?
In the early days of the internet, this was impossible—each HTTPS domain required its own dedicated IP address because the server didn't ...
🛠️ Production Runbook & Step-by-Step Resolution
Production Solution & Architecture
In the early days of the internet, this was impossible—each HTTPS domain required its own dedicated IP address because the server didn't know which website the client wanted until *after* the TLS encryption was established, but it needed to provide the right certificate *to* establish it. This is solved by SNI (Server Name Indication). SNI is an extension to the TLS protocol. During the very first step of the TLS handshake (the ClientHello packet), the user's browser transmits the requested hostname (clientA.com) in plaintext before encryption begins. The ALB reads this plaintext SNI extension, instantly searches its certificate store, selects the correct certificate for clientA.com, and completes the secure handshake.
- Immediate Triage: In the early days of the internet, this was impossible—each HTTPS domain required its own dedic
- Run targeted verification commands before modifying configuration.
- Automate permanent guardrails (CI check, alerts, IaC policy) to prevent recurrence.