* It is (in all but a couple of implementations I think) a *proxy* that the origin has contracted with. Could you please elaborate on your point?
It has a TLS cert that identifies itself as the origin. It doesn’t just terminate TLS, but it does work at the HTTP layer. How is it different from an origin that uses load-balancing to send you somewhere? Is www.facebook.com<http://www.facebook.com> a CDN or intermediary, or is it the origin?
_______________________________________________ TLS mailing list TLS@ietf.org https://www.ietf.org/mailman/listinfo/tls