• Rikudou_Sage
      link
      fedilink
      English
      1
      edit-2
      1 year ago

      It’s happening as part of the handshake. Probably not completely what it’s about, but it was the first that came to my mind.

      Edit: It has to happen before the encryption is established, because otherwise the server doesn’t know which certificate to use, because it doesn’t know which host is the client requesting. There’s also ESNI (encrypted SNI) to solve this but I’m not sure on how many servers actually deploy it.