Re : SSL w/ PCI best practices
Surya ARBY <[email protected]> Thu, 18 Feb 2010 19:28:16 +0000 (GMT)
| Newsgroups | gmane.comp.programming.load-balancing.general |
|---|---|
| Message-ID | <[email protected]> |
--===============0071420925== Content-Type: multipart/alternative; boundary="0-669102004-1266521296=:68702" --0-669102004-1266521296=:68702 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Hello David. Some examples : =0A- you can use self signed certificates on the server side, while you hav= e only one public certificate on your SSL accelerator - you can leverage TCP reuse / http multiplexing / SSL reuse to reduce the = number of SSL handshakes on the server side even if some entities on the cl= ient side do not support it. - using a SSL hardware card (only one) in the LB is far more scalable than = processing all the SSL load in software on the servers (you can put SSL car= ds in the servers too but byuing SSL cards for each servers can become quit= e expensive :) ) - you can use different ciphers on the front end and the back end (for exam= ple : AES / sha1 on the client side, RC4+md5 on the server side) to reduce = the load on the servers etc... regards, Surya --- En date de=C2=A0: Jeu 18.2.10, Van Ceylon, David <David.VanCeylon@qwest= .com> a =C3=A9crit=C2=A0: De: Van Ceylon, David <[email protected]> Objet: [load balancing] SSL w/ PCI best practices =C3=80: "'Load Balancing Mailing List'" <[email protected]> Date: Jeudi 18 f=C3=A9vrier 2010, 20h00 =0A=0A =0A =0A=0A=0A=0A=0AHello =E2=80=93=0A =0A =C2=A0 =0AI have a questio= n regarding the use of SSL while trying to maintain PCI compliance. =C2=A0I= f a load balancer/SSL accelerator is handling SSL, what advantage is that= =0A in terms of SSL offload if we must re-encrypt back to the servers?=C2= =A0 This essentially limits the load balancer to URI inspection and distrib= uting traffic.=C2=A0 There seems to be no advantage to handling Certs (othe= r than wildcard) or de-encryption. =C2=A0Forgive my=0A ignorance but I=E2= =80=99m looking for basic best practices in this situation. =0A =C2=A0 =0AT= hanks! =0A =C2=A0 =0ADavid VanCeylon =0A =C2=A0 =0A=0A =0A=0AThis communication is the property of Qwest and may contain confident= ial or =0Aprivileged information. Unauthorized use of this communication is strict= ly =0Aprohibited and may be unlawful. If you have received this communication =0Ain error, please immediately notify the sender by reply e-mail and destr= oy =0Aall copies of the communication and any attachments. =0A=0A =0A -----La pi=C3=A8ce jointe associ=C3=A9e suit----- _______________________________________________ lb-l mailing list [email protected] http://vegan.net/mailman/listinfo/lb-l Searchable Archive: http://vegan.net/lb/archive http://lbdigest.com Load Balancing Digest http://lbwiki.com Load Balancing Wiki =0A=0A=0A --0-669102004-1266521296=:68702 Content-Type: text/html; charset=utf-8 Content-Transfer-Encoding: quoted-printable <table cellspacing=3D"0" cellpadding=3D"0" border=3D"0" ><tr><td valign=3D"= top" style=3D"font: inherit;">Hello David.<br><br>Some examples :<br><br>= =0A- you can use self signed certificates on the server side, while you hav= e only one public certificate on your SSL accelerator<br><br>- you can leve= rage TCP reuse / http multiplexing / SSL reuse to reduce the number of SSL = handshakes on the server side even if some entities on the client side do n= ot support it.<br><br>- using a SSL hardware card (only one) in the LB is f= ar more scalable than processing all the SSL load in software on the server= s (you can put SSL cards in the servers too but byuing SSL cards for each s= ervers can become quite expensive :) )<br><br>- you can use different ciphe= rs on the front end and the back end (for example : AES / sha1 on the clien= t side, RC4+md5 on the server side) to reduce the load on the servers<br><b= r>etc...<br><br>regards,<br><br>Surya<br><br>--- En date de : <b>Jeu 1= 8.2.10, Van Ceylon, David <i><[email protected]></i></b> a = =C3=A9crit :<br><blockquote style=3D"border-left: 2px solid rgb(16, 16= , 255); margin-left: 5px; padding-left: 5px;"><br>De: Van Ceylon, David <= [email protected]><br>Objet: [load balancing] SSL w/ PCI best pr= actices<br>=C3=80: "'Load Balancing Mailing List'" <[email protected]><b= r>Date: Jeudi 18 f=C3=A9vrier 2010, 20h00<br><br><div id=3D"yiv1752802633">= =0A=0A =0A =0A<style>=0A<!--=0A#yiv1752802633 =0A#yiv1752802633 p.MsoNorma= l, #yiv1752802633 li.MsoNormal, #yiv1752802633 div.MsoNormal=0A=09{margin:0= in;margin-bottom:.0001pt;font-size:12.0pt;font-family:"Times New Roman";}= =0A#yiv1752802633 a:link, #yiv1752802633 span.MsoHyperlink=0A=09{color:blue= ;text-decoration:underline;}=0A#yiv1752802633 a:visited, #yiv1752802633 spa= n.MsoHyperlinkFollowed=0A=09{color:#606420;text-decoration:underline;}=0A#y= iv1752802633 span.EmailStyle17=0A=09{font-family:Arial;color:windowtext;}= =0A _filtered #yiv1752802633 {margin:1.0in 1.25in 1.0in 1.25in;}=0A#yiv1752= 802633 div.Section1=0A=09{}=0A-->=0A</style>=0A<div class=3D"Section1">=0A<= p class=3D"MsoNormal"><font face=3D"Arial" size=3D"2"><span style=3D"font-s= ize: 10pt; font-family: Arial;">Hello =E2=80=93=0A</span></font></p> =0A<p = class=3D"MsoNormal"><font face=3D"Arial" size=3D"2"><span style=3D"font-siz= e: 10pt; font-family: Arial;"> </span></font></p> =0A<p class=3D"MsoN= ormal"><font face=3D"Arial" size=3D"2"><span style=3D"font-size: 10pt; font= -family: Arial;">I have a question regarding the use of SSL while trying to= maintain PCI compliance. If a load balancer/SSL accelerator is handl= ing SSL, what advantage is that=0A in terms of SSL offload if we must re-en= crypt back to the servers? This essentially limits the load balancer = to URI inspection and distributing traffic. There seems to be no adva= ntage to handling Certs (other than wildcard) or de-encryption. Forgi= ve my=0A ignorance but I=E2=80=99m looking for basic best practices in this= situation.</span></font></p> =0A<p class=3D"MsoNormal"><font face=3D"Arial= " size=3D"2"><span style=3D"font-size: 10pt; font-family: Arial;"> </= span></font></p> =0A<p class=3D"MsoNormal"><font face=3D"Arial" size=3D"2">= <span style=3D"font-size: 10pt; font-family: Arial;">Thanks!</span></font><= /p> =0A<p class=3D"MsoNormal"><font face=3D"Arial" size=3D"2"><span style= =3D"font-size: 10pt; font-family: Arial;"> </span></font></p> =0A<p c= lass=3D"MsoNormal"><font face=3D"Arial" size=3D"2"><span style=3D"font-size= : 10pt; font-family: Arial;">David VanCeylon</span></font></p> =0A<p class= =3D"MsoNormal"><font face=3D"Times New Roman" size=3D"3"><span style=3D"fon= t-size: 12pt;"> </span></font></p> =0A</div>=0A<br>=0A<hr>=0A<font co= lor=3D"Gray" face=3D"Arial" size=3D"1">This communication is the property o= f Qwest and may contain confidential or<br>=0Aprivileged information. Unaut= horized use of this communication is strictly<br>=0Aprohibited and may be u= nlawful. If you have received this communication<br>=0Ain error, please imm= ediately notify the sender by reply e-mail and destroy<br>=0Aall copies of = the communication and any attachments.<br>=0A</font>=0A =0A</div><br>-----L= a pi=C3=A8ce jointe associ=C3=A9e suit-----<br><br><div class=3D"plainMail"= >_______________________________________________<br>lb-l mailing list<br><a= ymailto=3D"mailto:[email protected]" href=3D"/mc/[email protected]"= >[email protected]</a><br><a href=3D"http://vegan.net/mailman/listinfo/lb-l" t= arget=3D"_blank">http://vegan.net/mailman/listinfo/lb-l</a><br>Searchable A= rchive: <a href=3D"http://vegan.net/lb/archive" target=3D"_blank">http://ve= gan.net/lb/archive</a><br><a href=3D"http://lbdigest.com" target=3D"_blank"= >http://lbdigest.com</a> Load Balancing Digest<br><a href=3D"http://lbwiki.= com" target=3D"_blank">http://lbwiki.com</a> Load Balancing Wiki<br></div><= /blockquote></td></tr></table><br>=0A=0A=0A=0A=0A --0-669102004-1266521296=:68702-- --===============0071420925== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ lb-l mailing list [email protected] http://vegan.net/mailman/listinfo/lb-l Searchable Archive: http://vegan.net/lb/archive http://lbdigest.com Load Balancing Digest http://lbwiki.com Load Balancing Wiki --===============0071420925==--