• Rikudou_SageA
      link
      English
      2
      edit-2
      9 months ago

      It’s happening as part of the handshake. Probably not completely what it’s about, but it was the first that came to my mind.

      Edit: It has to happen before the encryption is established, because otherwise the server doesn’t know which certificate to use, because it doesn’t know which host is the client requesting. There’s also ESNI (encrypted SNI) to solve this but I’m not sure on how many servers actually deploy it.