Does Indy's IdHTTP send SNI when connecting to an HTTPS site using only an IP address?
29K reputation · 10 May 2022, 02:47 UTC
The goal is to confirm whether the IdHTTP component automatically includes the Server Name Indication (SNI) extension in the TLS ClientHello when the destination is specified by a raw IP address rather than a hostname.
Indy’s IdSSLIOHandlerSocketOpenSSL sets the SNI extension only when the Host property of IdHTTP is explicitly assigned; if the Host property is left blank or later overridden by a custom Host header, the SNI field may be omitted, potentially causing virtual‑host mismatches on servers that rely on SNI for certificate selection.
Uncertainty remains about whether this behavior is consistent across recent Indy versions, whether any internal fallback copies the IP address to SNI, and if developers must manually enforce SNI in such scenarios.
Does Indy automatically populate SNI from the IP address when Host is unset?
Can SNI be forced without setting the Host property?
Does the SNI handling differ between Indy 10.6.2 and earlier releases?