← Back to context

Comment by pimterry

9 hours ago

Same server also has an endpoint for that: http://no-tls.testserver.host. Sends RST for any attempted TLS connections, so clients always fall back to plain HTTP.

Also as a _long_ list of other specialist TLS endpoint configurations if you're interested, which can be arbitrarily combined, see https://testserver.host/#tls-endpoints.

That gives neat tricks like https://tls-v1-2--expired--incomplete-chain--http2.testserve...: only accepts TLS 1.2, then sends an expired certificate but fails to send the intermediate cert for the chain (so the client must infer it) and then negotiates HTTP/2 for the connection on top. Fun!