Re: [Alteon] problem with sslid and sticky session
ADC expert <[email protected]> Thu, 11 Feb 2010 13:53:15 +0530
| Newsgroups | gmane.comp.programming.load-balancing.general |
|---|---|
| Message-ID | <[email protected]> |
--===============0256354617== Content-Type: multipart/alternative; boundary=000e0cd1188acf639f047f4edc06 --000e0cd1188acf639f047f4edc06 Content-Type: text/plain; charset=ISO-8859-1 Hi Abbas, When you offload to SSL engines, it will encrypt the whole TCP payload. But, client application can still see the cookie. It should be this way, ADC should encrypt the cookie and give to SSL engine. By this client application does not understand the cookie. I also think, whats the big fuss about cookie..it is just for persistency..if the user modifies it -he would loose persistency and that is his problem.. What do you say? would any one want encrypted cookies? On Sat, Feb 6, 2010 at 3:29 AM, Ali Abbas <[email protected]> wrote: > Hi Travis > > On Fri, Feb 5, 2010 at 10:17 PM, Gamble, Travis < > [email protected]> wrote: > >> I know in some versions of IE, it regenerates the SSL ID every 2 minutes >> which would effectively break this functionality. >> >> Without looking at a bunch of sniffs, I'm not sure if that functionality >> is still true on recent versions, but if so, you may be stuck with source IP >> as your session persistence method. >> >> > > Don't forget, ISPs often proxies http and https through different proxies, > so you are going hit a wall here with pbind clientip > > Best bet, use pbind cookie and use an ssl offloader since the stream will > be encrypted, thus the application will not be able to see the cookie. > > Regards > > -- > Ali Abbas > Blog: http://alouche.net > > _______________________________________________ > lb-l mailing list > [email protected] > http://vegan.net/mailman/listinfo/lb-l > Searchable Archive: http://vegan.net/lb/archive > http://lbdigest.com Load Balancing Digest > http://lbwiki.com Load Balancing Wiki > > --000e0cd1188acf639f047f4edc06 Content-Type: text/html; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable Hi Abbas,<br>=A0 When you offload to SSL engines, it will encrypt the whole= TCP payload. But, client application can still see the cookie.<br><br>It s= hould be this way, ADC should encrypt the cookie and give to SSL engine. By= this client application does not understand the cookie. <br> I also think, whats the big fuss about cookie..it is just for persistency..= if the user modifies it -he would loose persistency and that is his problem= ..<br><br>What do you say? would any one want encrypted cookies?<br><br> <br><br><div class=3D"gmail_quote">On Sat, Feb 6, 2010 at 3:29 AM, Ali Abba= s <span dir=3D"ltr"><<a href=3D"mailto:[email protected]">alouche07@gm= ail.com</a>></span> wrote:<br><blockquote class=3D"gmail_quote" style=3D= "border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padd= ing-left: 1ex;"> Hi Travis<br><br><div class=3D"gmail_quote"><div class=3D"im">On Fri, Feb 5= , 2010 at 10:17 PM, Gamble, Travis <span dir=3D"ltr"><<a href=3D"mailto:= [email protected]" target=3D"_blank">Travis.Gamble@fraserhealth= .ca</a>></span> wrote:<br> <blockquote class=3D"gmail_quote" style=3D"border-left: 1px solid rgb(204, = 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;"> <div> <div dir=3D"ltr" align=3D"left"><span><font size=3D"2" color=3D"#0000ff" fa= ce=3D"Arial">I know in some versions of IE, it regenerates the SSL ID=20 every 2 minutes which would effectively break this=20 functionality.</font></span></div> <div dir=3D"ltr" align=3D"left"><span><font size=3D"2" color=3D"#0000ff" fa= ce=3D"Arial"></font></span>=A0</div> <div dir=3D"ltr" align=3D"left"><span><font size=3D"2" color=3D"#0000ff" fa= ce=3D"Arial">Without looking at a bunch of sniffs, I'm not sure if that= =20 functionality is still true on recent versions, but if so, you may be stuck= with=20 source IP as your session persistence method.</font></span></div> <div dir=3D"ltr" align=3D"left"><span><font size=3D"2" color=3D"#0000ff" fa= ce=3D"Arial"></font></span>=A0</div></div></blockquote></div><div><br>Don&#= 39;t forget, ISPs often proxies http and https through different proxies, s= o you are going hit a wall here with pbind clientip<br> <br>Best bet, use pbind cookie=A0 and use an ssl offloader since the stream= will be encrypted, thus the application will not be able to see the cookie= .<br><br>Regards<br><br clear=3D"all">--<br>Ali Abbas<br>Blog: <a href=3D"h= ttp://alouche.net" target=3D"_blank">http://alouche.net</a>=A0 <br></div></div> <br>_______________________________________________<br> lb-l mailing list<br> <a href=3D"mailto:[email protected]">[email protected]</a><br> <a href=3D"http://vegan.net/mailman/listinfo/lb-l" target=3D"_blank">http:/= /vegan.net/mailman/listinfo/lb-l</a><br> Searchable Archive: <a href=3D"http://vegan.net/lb/archive" target=3D"_blan= k">http://vegan.net/lb/archive</a><br> <a href=3D"http://lbdigest.com" target=3D"_blank">http://lbdigest.com</a> L= oad Balancing Digest<br> <a href=3D"http://lbwiki.com" target=3D"_blank">http://lbwiki.com</a> Load = Balancing Wiki<br> <br></blockquote></div><br><input id=3D"gwProxy" type=3D"hidden"><input onc= lick=3D"jsCall();" id=3D"jsProxy" type=3D"hidden"><div id=3D"refHTML"></div= > --000e0cd1188acf639f047f4edc06-- --===============0256354617== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ lb-l mailing list [email protected] http://vegan.net/mailman/listinfo/lb-l Searchable Archive: http://vegan.net/lb/archive http://lbdigest.com Load Balancing Digest http://lbwiki.com Load Balancing Wiki --===============0256354617==--