[{"data":1,"prerenderedAt":878},["ShallowReactive",2],{"content:\u002Fnetwork-protocol-optimization\u002Fhttp2-http3-and-connection-management\u002Fconnection-coalescing-and-certificates":3,"surroundings:\u002Fnetwork-protocol-optimization\u002Fhttp2-http3-and-connection-management\u002Fconnection-coalescing-and-certificates":870},{"id":4,"title":5,"body":6,"description":850,"extension":851,"meta":852,"navigation":863,"path":864,"seo":865,"stem":868,"__hash__":869},"content\u002Fnetwork-protocol-optimization\u002Fhttp2-http3-and-connection-management\u002Fconnection-coalescing-and-certificates\u002Findex.md","Connection Coalescing and Certificates",{"type":7,"value":8,"toc":832},"minimark",[9,13,33,48,187,192,227,231,237,243,249,255,259,264,271,275,282,371,375,390,394,397,506,510,517,521,546,550,553,619,623,626,630,656,660,666,672,678,684,688,700,709,718,727,736,745,754,763,772,781,790,794,817,822,825,828],[10,11,5],"h1",{"id":12},"connection-coalescing-and-certificates",[14,15,16,17,22,23,27,28,32],"p",{},"This guide is part of ",[18,19,21],"a",{"href":20},"\u002Fnetwork-protocol-optimization\u002Fhttp2-http3-and-connection-management\u002F","HTTP\u002F2, HTTP\u002F3 & Connection Management",", within ",[18,24,26],{"href":25},"\u002Fnetwork-protocol-optimization\u002F","Network & Server Response Optimization",". Every distinct hostname normally needs its own connection, with its own DNS lookup, handshakes and slow start. HTTP\u002F2 and HTTP\u002F3 allow an exception: if a browser already has a connection to a server, and a new hostname resolves to an IP address of that connection, and the server's certificate is valid for the new hostname, the browser may send requests for the new hostname over the existing connection. This is ",[29,30,31],"strong",{},"connection coalescing",".",[14,34,35,36,40,41,40,44,47],{},"Coalescing turns separate hostnames — ",[37,38,39],"code",{},"www.example.com",", ",[37,42,43],{},"static.example.com",[37,45,46],{},"img.example.com"," — into one connection, saving hundreds of milliseconds on mobile. It happens automatically when conditions are right, and silently fails when they are not: a certificate missing a name, a different IP set from the CDN, or an anonymous versus credentialed connection pool mismatch.",[14,49,50],{},[51,52,58,59,58,66,58,70,58,73,58,82,58,88,58,97,58,104,58,109,58,112,58,116,58,120,58,123,58,127,58,131,58,134,58,138,58,142,58,150,58,154,58,158,58,163,58,166,58,169,58,173,58,176,58,180,58,183,58],"svg",{"viewBox":53,"width":54,"role":55,"ariaLabel":56,"style":57},"0 0 760 318","100%","img","Conditions a browser checks before reusing an existing connection for a different hostname.","height:auto;max-width:760px;display:block;margin:1.75rem auto;font-family:inherit;color:var(--fp-svg-ink)"," ",[60,61],"rect",{"className":62,"x":64,"y":64,"width":54,"height":54,"fill":65},[63],"svg-canvas","0","#ffffff",[67,68,69],"title",{},"Conditions for connection coalescing",[71,72,56],"desc",{},[60,74],{"x":75,"y":75,"width":76,"height":77,"rx":78,"fill":79,"stroke":80,"style":81},"1","758","316","10","none","currentColor","stroke-opacity:0.18",[83,84,69],"text",{"x":85,"y":86,"fill":80,"style":87},"28.0","34.0","font-size:16px;font-weight:700",[60,89],{"x":90,"y":91,"width":92,"height":93,"rx":94,"fill":95,"stroke":95,"style":96},"72.0","56.0","660.0","51.0","6","#0466c8","fill-opacity:0.14;stroke-opacity:0.9",[83,98,103],{"x":99,"y":100,"fill":80,"style":101,"textAnchor":102},"86.0","77.0","font-size:13px;font-weight:700","start","HTTP\u002F2 or HTTP\u002F3 connection",[83,105,108],{"x":99,"y":106,"fill":80,"style":107,"textAnchor":102},"94.0","font-size:12px","HTTP\u002F1.1 connections are never coalesced",[60,110],{"x":90,"y":111,"width":92,"height":93,"rx":94,"fill":95,"stroke":95,"style":96},"119.0",[83,113,115],{"x":99,"y":114,"fill":80,"style":101,"textAnchor":102},"140.0","IP overlap",[83,117,119],{"x":99,"y":118,"fill":80,"style":107,"textAnchor":102},"157.0","New hostname resolves to an IP of the existing connection (Chromium)",[60,121],{"x":90,"y":122,"width":92,"height":93,"rx":94,"fill":95,"stroke":95,"style":96},"182.0",[83,124,126],{"x":99,"y":125,"fill":80,"style":101,"textAnchor":102},"203.0","Certificate covers the new name",[83,128,130],{"x":99,"y":129,"fill":80,"style":107,"textAnchor":102},"220.0","SAN list or wildcard includes the hostname",[60,132],{"x":90,"y":133,"width":92,"height":93,"rx":94,"fill":95,"stroke":95,"style":96},"245.0",[83,135,137],{"x":99,"y":136,"fill":80,"style":101,"textAnchor":102},"266.0","Same connection pool",[83,139,141],{"x":99,"y":140,"fill":80,"style":107,"textAnchor":102},"283.0","Credentialed vs anonymous requests use separate pools",[143,144],"line",{"x1":145,"y1":146,"x2":145,"y2":147,"stroke":80,"strokeWidth":148,"style":149},"43.0","95.5","130.5","1.5","stroke-opacity:0.3",[143,151],{"x1":145,"y1":152,"x2":145,"y2":153,"stroke":80,"strokeWidth":148,"style":149},"158.5","193.5",[143,155],{"x1":145,"y1":156,"x2":145,"y2":157,"stroke":80,"strokeWidth":148,"style":149},"221.5","256.5",[159,160],"circle",{"cx":145,"cy":161,"r":162,"fill":95},"81.5","13",[83,164,75],{"x":145,"y":99,"fill":65,"style":101,"textAnchor":165},"middle",[159,167],{"cx":145,"cy":168,"r":162,"fill":95},"144.5",[83,170,172],{"x":145,"y":171,"fill":65,"style":101,"textAnchor":165},"149.0","2",[159,174],{"cx":145,"cy":175,"r":162,"fill":95},"207.5",[83,177,179],{"x":145,"y":178,"fill":65,"style":101,"textAnchor":165},"212.0","3",[159,181],{"cx":145,"cy":182,"r":162,"fill":95},"270.5",[83,184,186],{"x":145,"y":185,"fill":65,"style":101,"textAnchor":165},"275.0","4",[188,189,191],"h2",{"id":190},"rapid-diagnosis","Rapid Diagnosis",[193,194,195,202,211,217],"ul",{},[196,197,198,201],"li",{},[29,199,200],{},"Enable the Connection ID column"," in the Network panel: requests to different hostnames with the same ID were coalesced.",[196,203,204,207,208,32],{},[29,205,206],{},"Check certificate SANs",": ",[37,209,210],{},"openssl s_client -connect www.example.com:443 -servername www.example.com | openssl x509 -noout -text | grep DNS:",[196,212,213,216],{},[29,214,215],{},"Compare DNS answers"," for the hostnames: overlapping IPs are required for Chromium coalescing.",[196,218,219,226],{},[29,220,221,222,225],{},"Check ",[37,223,224],{},"crossorigin"," usage",": fonts and CORS requests use anonymous connections, separate from credentialed ones.",[188,228,230],{"id":229},"root-cause-analysis","Root Cause Analysis",[14,232,233,236],{},[29,234,235],{},"1. Certificates without all names."," Each hostname has its own certificate.",[14,238,239,242],{},[29,240,241],{},"2. Different IPs."," CDNs may return different anycast IPs or pools for different hostnames.",[14,244,245,248],{},[29,246,247],{},"3. Connection pool split."," Anonymous (crossorigin) requests cannot use credentialed connections and vice versa.",[14,250,251,254],{},[29,252,253],{},"4. Different CDNs or providers."," Hostnames served by different infrastructure cannot coalesce.",[188,256,258],{"id":257},"step-by-step-resolution","Step-by-Step Resolution",[260,261,263],"h3",{"id":262},"_1-use-a-certificate-that-covers-all-hostnames","1. Use a certificate that covers all hostnames",[14,265,266,267,270],{},"Issue a certificate with all relevant hostnames in the Subject Alternative Name list, or a wildcard (",[37,268,269],{},"*.example.com",") that covers subdomains. Serve the same certificate for all of them.",[260,272,274],{"id":273},"_2-serve-hostnames-from-the-same-ips","2. Serve hostnames from the same IPs",[14,276,277,278,281],{},"Point all hostnames at the same CDN configuration (or the same anycast IPs). Check with ",[37,279,280],{},"dig +short"," that answers overlap.",[283,284,289],"pre",{"className":285,"code":286,"language":287,"meta":288,"style":288},"language-bash shiki shiki-themes github-light-high-contrast github-dark-high-contrast github-light-high-contrast","for h in www.example.com static.example.com img.example.com; do echo \"$h: $(dig +short $h | tr '\\n' ' ')\"; done\n# trade-off: CDNs may rotate IPs per query; overlap needs to exist for the\n# browser's cached answers, so using the same CDN property is most reliable.\n","bash","",[37,290,291,358,365],{"__ignoreMap":288},[292,293,295,299,303,306,310,313,316,319,322,326,329,332,335,339,342,344,347,350,353,355],"span",{"class":143,"line":294},1,[292,296,298],{"class":297},"sPARh","for",[292,300,302],{"class":301},"saISM"," h ",[292,304,305],{"class":297},"in",[292,307,309],{"class":308},"sZ8jY"," www.example.com",[292,311,312],{"class":308}," static.example.com",[292,314,315],{"class":308}," img.example.com",[292,317,318],{"class":301},"; ",[292,320,321],{"class":297},"do",[292,323,325],{"class":324},"sPXB4"," echo",[292,327,328],{"class":308}," \"",[292,330,331],{"class":301},"$h",[292,333,334],{"class":308},": $(",[292,336,338],{"class":337},"sQw3B","dig",[292,340,341],{"class":308}," +short ",[292,343,331],{"class":301},[292,345,346],{"class":297}," |",[292,348,349],{"class":337}," tr",[292,351,352],{"class":308}," '\\n' ' ')\"",[292,354,318],{"class":301},[292,356,357],{"class":297},"done\n",[292,359,361],{"class":143,"line":360},2,[292,362,364],{"class":363},"sjfSM","# trade-off: CDNs may rotate IPs per query; overlap needs to exist for the\n",[292,366,368],{"class":143,"line":367},3,[292,369,370],{"class":363},"# browser's cached answers, so using the same CDN property is most reliable.\n",[260,372,374],{"id":373},"_3-align-credentials-modes","3. Align credentials modes",[14,376,377,378,380,381,383,384,386,387,389],{},"Fonts and other ",[37,379,224],{}," requests use anonymous connections. If the page loads fonts from ",[37,382,43],{}," with ",[37,385,224],{}," and images without, the browser may need two connections. Preconnect with and without ",[37,388,224],{}," only where both are needed.",[260,391,393],{"id":392},"_4-verify-in-the-browser","4. Verify in the browser",[14,395,396],{},"Reload with the Connection ID column visible; requests to the coalesced hostnames should share the main document's connection ID.",[14,398,399],{},[51,400,58,403,58,406,58,409,58,411,58,414,58,416,58,421,58,427,58,431,58,434,58,437,58,440,58,443,58,447,58,452,58,455,58,457,58,459,58,462,58,466,58,468,58,470,58,472,58,474,58,477,58,481,58,483,58,486,58,488,58,490,58,493,58,497,58,499,58,502,58,504,58],{"viewBox":401,"width":54,"role":55,"ariaLabel":402,"style":57},"0 0 760 228","Whether a browser can coalesce static and image hostnames onto the main connection under different configurations.",[60,404],{"className":405,"x":64,"y":64,"width":54,"height":54,"fill":65},[63],[67,407,408],{},"Coalescing outcomes for three hostnames",[71,410,402],{},[60,412],{"x":75,"y":75,"width":76,"height":413,"rx":78,"fill":79,"stroke":80,"style":81},"226",[83,415,408],{"x":85,"y":86,"fill":80,"style":87},[60,417],{"x":85,"y":91,"width":418,"height":419,"rx":64,"fill":80,"stroke":80,"style":420},"206.1","30.0","fill-opacity:0.06;stroke-opacity:0.4",[83,422,426],{"x":423,"y":424,"fill":80,"style":425,"textAnchor":102},"38.0","75.5","font-size:12.5px;font-weight:700","Configuration",[60,428],{"x":429,"y":91,"width":430,"height":419,"rx":64,"fill":80,"stroke":80,"style":420},"234.1","248.9",[83,432,43],{"x":433,"y":424,"fill":80,"style":425,"textAnchor":165},"358.6",[60,435],{"x":436,"y":91,"width":430,"height":419,"rx":64,"fill":80,"stroke":80,"style":420},"483.1",[83,438,46],{"x":439,"y":424,"fill":80,"style":425,"textAnchor":165},"607.5",[60,441],{"x":85,"y":99,"width":418,"height":419,"rx":64,"fill":79,"stroke":80,"style":442},"stroke-opacity:0.35",[83,444,446],{"x":423,"y":445,"fill":80,"style":425,"textAnchor":102},"105.5","Separate certificates",[60,448],{"x":429,"y":99,"width":430,"height":419,"rx":64,"fill":449,"stroke":450,"style":451},"#ffc300","#b8860b","fill-opacity:0.24;stroke-opacity:0.9",[83,453,454],{"x":433,"y":445,"fill":80,"style":107,"textAnchor":165},"new connection",[60,456],{"x":436,"y":99,"width":430,"height":419,"rx":64,"fill":449,"stroke":450,"style":451},[83,458,454],{"x":439,"y":445,"fill":80,"style":107,"textAnchor":165},[60,460],{"x":85,"y":461,"width":418,"height":419,"rx":64,"fill":79,"stroke":80,"style":442},"116.0",[83,463,465],{"x":423,"y":464,"fill":80,"style":425,"textAnchor":102},"135.5","Shared SAN cert, different IPs",[60,467],{"x":429,"y":461,"width":430,"height":419,"rx":64,"fill":449,"stroke":450,"style":451},[83,469,454],{"x":433,"y":464,"fill":80,"style":107,"textAnchor":165},[60,471],{"x":436,"y":461,"width":430,"height":419,"rx":64,"fill":449,"stroke":450,"style":451},[83,473,454],{"x":439,"y":464,"fill":80,"style":107,"textAnchor":165},[60,475],{"x":85,"y":476,"width":418,"height":419,"rx":64,"fill":79,"stroke":80,"style":442},"146.0",[83,478,480],{"x":423,"y":479,"fill":80,"style":425,"textAnchor":102},"165.5","Shared cert + same CDN IPs",[60,482],{"x":429,"y":476,"width":430,"height":419,"rx":64,"fill":95,"stroke":95,"style":96},[83,484,485],{"x":433,"y":479,"fill":80,"style":107,"textAnchor":165},"coalesced",[60,487],{"x":436,"y":476,"width":430,"height":419,"rx":64,"fill":95,"stroke":95,"style":96},[83,489,485],{"x":439,"y":479,"fill":80,"style":107,"textAnchor":165},[60,491],{"x":85,"y":492,"width":418,"height":419,"rx":64,"fill":79,"stroke":80,"style":442},"176.0",[83,494,496],{"x":423,"y":495,"fill":80,"style":425,"textAnchor":102},"195.5","Same, but fonts with crossorigin",[60,498],{"x":429,"y":492,"width":430,"height":419,"rx":64,"fill":80,"stroke":80,"style":420},[83,500,501],{"x":433,"y":495,"fill":80,"style":107,"textAnchor":165},"anonymous pool separate",[60,503],{"x":436,"y":492,"width":430,"height":419,"rx":64,"fill":95,"stroke":95,"style":96},[83,505,485],{"x":439,"y":495,"fill":80,"style":107,"textAnchor":165},[188,507,509],{"id":508},"verification","Verification",[14,511,512,513,516],{},"The Network panel should show one connection ID for the main document and coalesced asset hostnames. Connection setup timing for asset requests should be zero. Resource Timing for coalesced hosts shows ",[37,514,515],{},"connectStart === connectEnd",". In RUM, compare resource load delay for critical assets before and after.",[188,518,520],{"id":519},"worked-example-a-university-website","Worked Example: A University Website",[14,522,523,524,527,528,531,532,535,536,539,540,542,543,545],{},"A university site loaded pages from ",[37,525,526],{},"www",", CSS and JS from ",[37,529,530],{},"assets",", images from ",[37,533,534],{},"media",", and fonts from ",[37,537,538],{},"fonts"," — four hostnames, each with its own certificate, though all ran on the same CDN. Pages opened five connections (including an anonymous one for fonts). The team issued one certificate covering all four names and moved them into one CDN property so DNS answers matched. Chrome then coalesced ",[37,541,530],{}," and ",[37,544,534],{}," onto the main connection, and fonts used one anonymous connection. Connections before LCP fell from five to two, and LCP p75 on mobile improved by 280ms.",[188,547,549],{"id":548},"coalescing-vs-consolidation","Coalescing vs Consolidation",[14,551,552],{},"Coalescing is a safety net, not a design goal. Consolidating everything onto one hostname is simpler and works in every browser and pool. Coalescing helps when separate hostnames must exist — for organisational reasons, legacy URLs, or security isolation — and makes them nearly free. Browsers implement coalescing slightly differently (Chromium requires IP overlap; Firefox can also use HTTP\u002F2 ORIGIN frames, where servers declare the origins they serve), so do not depend on it for critical paths if you can consolidate instead.",[14,554,555],{},[51,556,58,559,58,562,58,565,58,567,58,570,58,572,58,579,58,585,58,590,58,594,58,599,58,603,58,607,58,611,58,613,58],{"viewBox":557,"width":54,"role":55,"ariaLabel":558,"style":57},"0 0 760 189","Bar chart of connections opened before LCP for a site with four hostnames under different configurations.",[60,560],{"className":561,"x":64,"y":64,"width":54,"height":54,"fill":65},[63],[67,563,564],{},"Connections opened before LCP",[71,566,558],{},[60,568],{"x":75,"y":75,"width":76,"height":569,"rx":78,"fill":79,"stroke":80,"style":81},"187",[83,571,564],{"x":85,"y":86,"fill":80,"style":87},[83,573,578],{"x":574,"y":575,"fill":80,"style":576,"textAnchor":577},"212.6","70.0","font-size:13px","end","Separate certs and IPs",[60,580],{"x":581,"y":91,"width":582,"height":583,"rx":179,"fill":79,"stroke":80,"style":584},"224.6","443.4","19","fill-opacity:0.7;stroke-opacity:0.35",[83,586,589],{"x":587,"y":575,"fill":80,"style":588},"674.0","font-size:12px;font-weight:600","5connections",[83,591,593],{"x":574,"y":592,"fill":80,"style":576,"textAnchor":577},"101.0","Shared cert and IPs (coalesced)",[60,595],{"x":581,"y":596,"width":597,"height":583,"rx":179,"fill":95,"stroke":95,"style":598},"87.0","177.4","fill-opacity:0.55;stroke-opacity:0.9",[83,600,602],{"x":601,"y":592,"fill":80,"style":588},"407.9","2connections",[83,604,606],{"x":574,"y":605,"fill":80,"style":576,"textAnchor":577},"132.0","Consolidated hostname",[60,608],{"x":581,"y":609,"width":597,"height":583,"rx":179,"fill":449,"stroke":450,"style":610},"118.0","fill-opacity:0.7;stroke-opacity:0.9",[83,612,602],{"x":601,"y":605,"fill":80,"style":588},[83,614,618],{"x":85,"y":615,"fill":616,"style":617},"167.0","#51617a","font-size:12.5px","One extra anonymous connection remains for crossorigin fonts in both cases.",[188,620,622],{"id":621},"auditing-coalescing-across-a-site","Auditing Coalescing Across a Site",[14,624,625],{},"Coalescing can break silently when a certificate is renewed without one of the names, or when a subdomain moves to a different CDN property. Add a periodic check that resolves each hostname used on key pages, compares the IP sets, and inspects the certificate served for each to confirm it lists all the names. In the browser, a synthetic test can count distinct connection IDs on page load (via the Chrome DevTools Protocol) and alert if the number rises. Treat the number of connections before LCP as a tracked metric, like bundle size, so changes to infrastructure show up in the same dashboards as code changes.",[188,627,629],{"id":628},"common-mistakes","Common Mistakes",[193,631,632,638,644,650],{},[196,633,634,637],{},[29,635,636],{},"Assuming a wildcard certificate is enough."," IPs must overlap too.",[196,639,640,643],{},[29,641,642],{},"Mixing CDNs for subdomains."," Different infrastructure prevents coalescing.",[196,645,646,649],{},[29,647,648],{},"Overusing crossorigin."," Splits requests into the anonymous pool unnecessarily.",[196,651,652,655],{},[29,653,654],{},"Huge SAN lists."," Very large certificates add bytes to every handshake.",[188,657,659],{"id":658},"edge-cases","Edge Cases",[14,661,662,665],{},[29,663,664],{},"Third-party domains."," You cannot coalesce with origins you do not control.",[14,667,668,671],{},[29,669,670],{},"Misdirected requests."," If a server receives a coalesced request for a hostname it does not serve, it should respond with 421 Misdirected Request, and the browser retries on a new connection.",[14,673,674,677],{},[29,675,676],{},"Privacy considerations."," Some browsers limit coalescing in specific privacy modes.",[14,679,680,683],{},[29,681,682],{},"HTTP\u002F3."," Coalescing applies to HTTP\u002F3 as well, under the same certificate rules.",[188,685,687],{"id":686},"faq","FAQ",[689,690,693,697],"details",{"className":691},[692],"faq-item",[694,695,696],"summary",{},"What is connection coalescing?",[14,698,699],{},"Reusing one HTTP\u002F2 or HTTP\u002F3 connection for requests to several hostnames, when the server's certificate covers them and, in Chromium, they resolve to overlapping IPs.",[689,701,703,706],{"className":702},[692],[694,704,705],{},"How can I tell if coalescing happens?",[14,707,708],{},"Show the Connection ID column in DevTools' Network panel. Requests to different hostnames with the same ID share a connection.",[689,710,712,715],{"className":711},[692],[694,713,714],{},"Does a wildcard certificate enable coalescing?",[14,716,717],{},"It satisfies the certificate requirement for subdomains. IP overlap is also required in Chromium.",[689,719,721,724],{"className":720},[692],[694,722,723],{},"Why do fonts use a separate connection?",[14,725,726],{},"Fonts are fetched in CORS anonymous mode, which uses a separate connection pool from credentialed requests.",[689,728,730,733],{"className":729},[692],[694,731,732],{},"What is the ORIGIN frame?",[14,734,735],{},"An HTTP\u002F2 extension where the server lists the origins it is authoritative for, letting supporting browsers coalesce without relying on DNS overlap.",[689,737,739,742],{"className":738},[692],[694,740,741],{},"Is coalescing better than consolidation?",[14,743,744],{},"No. Consolidating onto one hostname is simpler and more reliable. Coalescing reduces the cost of hostnames that must stay separate.",[689,746,748,751],{"className":747},[692],[694,749,750],{},"Does coalescing work across different CDNs?",[14,752,753],{},"No. Coalescing requires the same server infrastructure to answer for both hostnames.",[689,755,757,760],{"className":756},[692],[694,758,759],{},"Can coalescing cause errors?",[14,761,762],{},"Rarely. If a server receives a request for a hostname it does not serve on that connection, it should return 421 Misdirected Request, and browsers retry on a new connection.",[689,764,766,769],{"className":765},[692],[694,767,768],{},"Do HTTP\u002F3 connections coalesce too?",[14,770,771],{},"Yes. The same certificate and authority rules apply, so hostnames that coalesce over HTTP\u002F2 can also share an HTTP\u002F3 connection.",[689,773,775,778],{"className":774},[692],[694,776,777],{},"Does preconnect help when coalescing works?",[14,779,780],{},"No. If a hostname will be coalesced onto an existing connection, a preconnect to it is redundant and may even open an unnecessary separate connection.",[689,782,784,787],{"className":783},[692],[694,785,786],{},"Is a wildcard certificate a security risk?",[14,788,789],{},"It widens the impact if the private key leaks, since it covers every subdomain. A SAN certificate listing specific hostnames is a narrower alternative that still enables coalescing.",[188,791,793],{"id":792},"related","Related",[193,795,796,803,810],{},[196,797,798,802],{},[18,799,801],{"href":800},"\u002Fnetwork-protocol-optimization\u002Fhttp2-http3-and-connection-management\u002Fwhy-domain-sharding-hurts-on-http2\u002F","Why domain sharding hurts on HTTP\u002F2"," — consolidating hostnames.",[196,804,805,809],{},[18,806,808],{"href":807},"\u002Fadvanced-caching-strategies-cdn-architecture\u002Fresource-hints-and-early-hints\u002Fdns-prefetch-vs-preconnect\u002F","DNS prefetch vs preconnect"," — preconnect and connection pools.",[196,811,812,816],{},[18,813,815],{"href":814},"\u002Fnetwork-protocol-optimization\u002Ftime-to-first-byte-optimization\u002Feliminating-redirect-chains\u002F","Eliminating redirect chains"," — other connection costs before TTFB.",[818,819,821],"script",{"type":820},"application\u002Fld+json","\n{\n  \"@context\": \"https:\u002F\u002Fschema.org\",\n  \"@type\": \"HowTo\",\n  \"name\": \"Connection Coalescing and Certificates\",\n  \"description\": \"How HTTP\u002F2 and HTTP\u002F3 connection coalescing works, what prevents it, and how to configure certificates and DNS so separate hostnames share connections.\",\n  \"step\": [\n    {\n      \"@type\": \"HowToStep\",\n      \"position\": 1,\n      \"name\": \"Use a certificate that covers all hostnames\",\n      \"text\": \"Issue a certificate with all relevant hostnames in the Subject Alternative Name list, or a wildcard (*.example.com) that covers subdomains.\"\n    },\n    {\n      \"@type\": \"HowToStep\",\n      \"position\": 2,\n      \"name\": \"Serve hostnames from the same IPs\",\n      \"text\": \"Point all hostnames at the same CDN configuration (or the same anycast IPs).\"\n    },\n    {\n      \"@type\": \"HowToStep\",\n      \"position\": 3,\n      \"name\": \"Align credentials modes\",\n      \"text\": \"Fonts and other crossorigin requests use anonymous connections.\"\n    },\n    {\n      \"@type\": \"HowToStep\",\n      \"position\": 4,\n      \"name\": \"Verify in the browser\",\n      \"text\": \"Reload with the Connection ID column visible; requests to the coalesced hostnames should share the main document's connection ID.\"\n    }\n  ]\n}\n",[818,823,824],{"type":820},"\n{\n  \"@context\": \"https:\u002F\u002Fschema.org\",\n  \"@type\": \"TechArticle\",\n  \"headline\": \"Connection Coalescing and Certificates\",\n  \"description\": \"How HTTP\u002F2 and HTTP\u002F3 connection coalescing works, what prevents it, and how to configure certificates and DNS so separate hostnames share connections.\",\n  \"datePublished\": \"2026-10-06\",\n  \"dateModified\": \"2026-10-06\",\n  \"author\": {\n    \"@type\": \"Organization\",\n    \"name\": \"frontend-performance.com\"\n  },\n  \"publisher\": {\n    \"@type\": \"Organization\",\n    \"name\": \"frontend-performance.com\"\n  },\n  \"mainEntityOfPage\": {\n    \"@type\": \"WebPage\",\n    \"@id\": \"https:\u002F\u002Ffrontend-performance.com\u002Fnetwork-protocol-optimization\u002Fhttp2-http3-and-connection-management\u002Fconnection-coalescing-and-certificates\u002F\"\n  }\n}\n",[818,826,827],{"type":820},"\n{\n  \"@context\": \"https:\u002F\u002Fschema.org\",\n  \"@type\": \"BreadcrumbList\",\n  \"itemListElement\": [\n    {\n      \"@type\": \"ListItem\",\n      \"position\": 1,\n      \"name\": \"Home\",\n      \"item\": \"https:\u002F\u002Ffrontend-performance.com\u002F\"\n    },\n    {\n      \"@type\": \"ListItem\",\n      \"position\": 2,\n      \"name\": \"Network & Server Response Optimization\",\n      \"item\": \"https:\u002F\u002Ffrontend-performance.com\u002Fnetwork-protocol-optimization\u002F\"\n    },\n    {\n      \"@type\": \"ListItem\",\n      \"position\": 3,\n      \"name\": \"HTTP\u002F2, HTTP\u002F3 & Connection Management\",\n      \"item\": \"https:\u002F\u002Ffrontend-performance.com\u002Fnetwork-protocol-optimization\u002Fhttp2-http3-and-connection-management\u002F\"\n    },\n    {\n      \"@type\": \"ListItem\",\n      \"position\": 4,\n      \"name\": \"Connection Coalescing and Certificates\",\n      \"item\": \"https:\u002F\u002Ffrontend-performance.com\u002Fnetwork-protocol-optimization\u002Fhttp2-http3-and-connection-management\u002Fconnection-coalescing-and-certificates\u002F\"\n    }\n  ]\n}\n",[829,830,831],"style",{},"html pre.shiki code .sPARh, html code.shiki .sPARh{--shiki-default:#A0111F;--shiki-dark:#FF9492;--shiki-light:#A0111F}html pre.shiki code .saISM, html code.shiki .saISM{--shiki-default:#0E1116;--shiki-dark:#F0F3F6;--shiki-light:#0E1116}html pre.shiki code .sZ8jY, html code.shiki .sZ8jY{--shiki-default:#032563;--shiki-dark:#ADDCFF;--shiki-light:#032563}html pre.shiki code .sPXB4, html code.shiki .sPXB4{--shiki-default:#023B95;--shiki-dark:#91CBFF;--shiki-light:#023B95}html pre.shiki code .sQw3B, html code.shiki .sQw3B{--shiki-default:#702C00;--shiki-dark:#FFB757;--shiki-light:#702C00}html pre.shiki code .sjfSM, html code.shiki .sjfSM{--shiki-default:#66707B;--shiki-dark:#BDC4CC;--shiki-light:#66707B}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}",{"title":288,"searchDepth":360,"depth":360,"links":833},[834,835,836,842,843,844,845,846,847,848,849],{"id":190,"depth":360,"text":191},{"id":229,"depth":360,"text":230},{"id":257,"depth":360,"text":258,"children":837},[838,839,840,841],{"id":262,"depth":367,"text":263},{"id":273,"depth":367,"text":274},{"id":373,"depth":367,"text":374},{"id":392,"depth":367,"text":393},{"id":508,"depth":360,"text":509},{"id":519,"depth":360,"text":520},{"id":548,"depth":360,"text":549},{"id":621,"depth":360,"text":622},{"id":628,"depth":360,"text":629},{"id":658,"depth":360,"text":659},{"id":686,"depth":360,"text":687},{"id":792,"depth":360,"text":793},"How HTTP\u002F2 and HTTP\u002F3 connection coalescing works, what prevents it, and how to configure certificates and DNS so separate hostnames share connections.","md",{"slug":12,"type":853,"breadcrumb":854,"datePublished":862,"dateModified":862},"article",[855,858,859,860],{"name":856,"url":857},"Home","\u002F",{"name":26,"url":25},{"name":21,"url":20},{"name":5,"url":861},"\u002Fnetwork-protocol-optimization\u002Fhttp2-http3-and-connection-management\u002Fconnection-coalescing-and-certificates\u002F","2026-10-06",true,"\u002Fnetwork-protocol-optimization\u002Fhttp2-http3-and-connection-management\u002Fconnection-coalescing-and-certificates",{"title":866,"description":867},"HTTP\u002F2 Connection Coalescing and Certificates","Browsers can reuse one HTTP\u002F2 or HTTP\u002F3 connection across hostnames that share IPs and a certificate. Configure SANs, DNS and CDNs so coalescing actually happens.","network-protocol-optimization\u002Fhttp2-http3-and-connection-management\u002Fconnection-coalescing-and-certificates\u002Findex","Ab1uDJ8QYWJ7UKZdsmoth4Ob9FiIog59RpI5kaCQ__c",[871,874],{"title":21,"path":872,"stem":873,"children":-1},"\u002Fnetwork-protocol-optimization\u002Fhttp2-http3-and-connection-management","network-protocol-optimization\u002Fhttp2-http3-and-connection-management\u002Findex",{"title":875,"path":876,"stem":877,"children":-1},"Diagnosing Head-of-Line Blocking","\u002Fnetwork-protocol-optimization\u002Fhttp2-http3-and-connection-management\u002Fdiagnosing-head-of-line-blocking","network-protocol-optimization\u002Fhttp2-http3-and-connection-management\u002Fdiagnosing-head-of-line-blocking\u002Findex",1791308073482]