Re : SSL w/ PCI best practices

Surya ARBY <[email protected]> Thu, 18 Feb 2010 19:28:16 +0000 (GMT)
Newsgroups gmane.comp.programming.load-balancing.general
Message-ID <[email protected]>
--===============0071420925==
Content-Type: multipart/alternative; boundary="0-669102004-1266521296=:68702"

--0-669102004-1266521296=:68702
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable

Hello David.

Some examples :

=0A- you can use self signed certificates on the server side, while you hav=
e only one public certificate on your SSL accelerator

- you can leverage TCP reuse / http multiplexing / SSL reuse to reduce the =
number of SSL handshakes on the server side even if some entities on the cl=
ient side do not support it.

- using a SSL hardware card (only one) in the LB is far more scalable than =
processing all the SSL load in software on the servers (you can put SSL car=
ds in the servers too but byuing SSL cards for each servers can become quit=
e expensive :) )

- you can use different ciphers on the front end and the back end (for exam=
ple : AES / sha1 on the client side, RC4+md5 on the server side) to reduce =
the load on the servers

etc...

regards,

Surya

--- En date de=C2=A0: Jeu 18.2.10, Van Ceylon, David <David.VanCeylon@qwest=
.com> a =C3=A9crit=C2=A0:

De: Van Ceylon, David <[email protected]>
Objet: [load balancing] SSL w/ PCI best practices
=C3=80: "'Load Balancing Mailing List'" <[email protected]>
Date: Jeudi 18 f=C3=A9vrier 2010, 20h00

=0A=0A =0A =0A=0A=0A=0A=0AHello =E2=80=93=0A =0A =C2=A0 =0AI have a questio=
n regarding the use of SSL while trying to maintain PCI compliance. =C2=A0I=
f a load balancer/SSL accelerator is handling SSL, what advantage is that=
=0A in terms of SSL offload if we must re-encrypt back to the servers?=C2=
=A0 This essentially limits the load balancer to URI inspection and distrib=
uting traffic.=C2=A0 There seems to be no advantage to handling Certs (othe=
r than wildcard) or de-encryption. =C2=A0Forgive my=0A ignorance but I=E2=
=80=99m looking for basic best practices in this situation. =0A =C2=A0 =0AT=
hanks! =0A =C2=A0 =0ADavid VanCeylon =0A =C2=A0 =0A=0A
=0A=0AThis communication is the property of Qwest and may contain confident=
ial or
=0Aprivileged information. Unauthorized use of this communication is strict=
ly
=0Aprohibited and may be unlawful. If you have received this communication
=0Ain error, please immediately notify the sender by reply e-mail and destr=
oy
=0Aall copies of the communication and any attachments.
=0A=0A =0A
-----La pi=C3=A8ce jointe associ=C3=A9e suit-----

_______________________________________________
lb-l mailing list
[email protected]
http://vegan.net/mailman/listinfo/lb-l
Searchable Archive: http://vegan.net/lb/archive
http://lbdigest.com Load Balancing Digest
http://lbwiki.com Load Balancing Wiki
=0A=0A=0A      
--0-669102004-1266521296=:68702
Content-Type: text/html; charset=utf-8
Content-Transfer-Encoding: quoted-printable

<table cellspacing=3D"0" cellpadding=3D"0" border=3D"0" ><tr><td valign=3D"=
top" style=3D"font: inherit;">Hello David.<br><br>Some examples :<br><br>=
=0A- you can use self signed certificates on the server side, while you hav=
e only one public certificate on your SSL accelerator<br><br>- you can leve=
rage TCP reuse / http multiplexing / SSL reuse to reduce the number of SSL =
handshakes on the server side even if some entities on the client side do n=
ot support it.<br><br>- using a SSL hardware card (only one) in the LB is f=
ar more scalable than processing all the SSL load in software on the server=
s (you can put SSL cards in the servers too but byuing SSL cards for each s=
ervers can become quite expensive :) )<br><br>- you can use different ciphe=
rs on the front end and the back end (for example : AES / sha1 on the clien=
t side, RC4+md5 on the server side) to reduce the load on the servers<br><b=
r>etc...<br><br>regards,<br><br>Surya<br><br>--- En date de&nbsp;: <b>Jeu 1=
8.2.10, Van Ceylon, David <i>&lt;[email protected]&gt;</i></b> a =
=C3=A9crit&nbsp;:<br><blockquote style=3D"border-left: 2px solid rgb(16, 16=
,
 255); margin-left: 5px; padding-left: 5px;"><br>De: Van Ceylon, David &lt;=
[email protected]&gt;<br>Objet: [load balancing] SSL w/ PCI best pr=
actices<br>=C3=80: "'Load Balancing Mailing List'" &lt;[email protected]&gt;<b=
r>Date: Jeudi 18 f=C3=A9vrier 2010, 20h00<br><br><div id=3D"yiv1752802633">=
=0A=0A =0A =0A<style>=0A<!--=0A#yiv1752802633  =0A#yiv1752802633 p.MsoNorma=
l, #yiv1752802633 li.MsoNormal, #yiv1752802633 div.MsoNormal=0A=09{margin:0=
in;margin-bottom:.0001pt;font-size:12.0pt;font-family:"Times New Roman";}=
=0A#yiv1752802633 a:link, #yiv1752802633 span.MsoHyperlink=0A=09{color:blue=
;text-decoration:underline;}=0A#yiv1752802633 a:visited, #yiv1752802633 spa=
n.MsoHyperlinkFollowed=0A=09{color:#606420;text-decoration:underline;}=0A#y=
iv1752802633 span.EmailStyle17=0A=09{font-family:Arial;color:windowtext;}=
=0A _filtered #yiv1752802633 {margin:1.0in 1.25in 1.0in 1.25in;}=0A#yiv1752=
802633 div.Section1=0A=09{}=0A-->=0A</style>=0A<div class=3D"Section1">=0A<=
p class=3D"MsoNormal"><font face=3D"Arial" size=3D"2"><span style=3D"font-s=
ize: 10pt; font-family: Arial;">Hello =E2=80=93=0A</span></font></p> =0A<p =
class=3D"MsoNormal"><font face=3D"Arial" size=3D"2"><span style=3D"font-siz=
e: 10pt; font-family: Arial;"> &nbsp;</span></font></p> =0A<p class=3D"MsoN=
ormal"><font face=3D"Arial" size=3D"2"><span style=3D"font-size: 10pt; font=
-family: Arial;">I have a question regarding the use of SSL while trying to=
 maintain PCI compliance. &nbsp;If a load balancer/SSL accelerator is handl=
ing SSL, what advantage is that=0A in terms of SSL offload if we must re-en=
crypt back to the servers?&nbsp; This essentially limits the load balancer =
to URI inspection and distributing traffic.&nbsp; There seems to be no adva=
ntage to handling Certs (other than wildcard) or de-encryption. &nbsp;Forgi=
ve my=0A ignorance but I=E2=80=99m looking for basic best practices in this=
 situation.</span></font></p> =0A<p class=3D"MsoNormal"><font face=3D"Arial=
" size=3D"2"><span style=3D"font-size: 10pt; font-family: Arial;"> &nbsp;</=
span></font></p> =0A<p class=3D"MsoNormal"><font face=3D"Arial" size=3D"2">=
<span style=3D"font-size: 10pt; font-family: Arial;">Thanks!</span></font><=
/p> =0A<p class=3D"MsoNormal"><font face=3D"Arial" size=3D"2"><span style=
=3D"font-size: 10pt; font-family: Arial;"> &nbsp;</span></font></p> =0A<p c=
lass=3D"MsoNormal"><font face=3D"Arial" size=3D"2"><span style=3D"font-size=
: 10pt; font-family: Arial;">David VanCeylon</span></font></p> =0A<p class=
=3D"MsoNormal"><font face=3D"Times New Roman" size=3D"3"><span style=3D"fon=
t-size: 12pt;"> &nbsp;</span></font></p> =0A</div>=0A<br>=0A<hr>=0A<font co=
lor=3D"Gray" face=3D"Arial" size=3D"1">This communication is the property o=
f Qwest and may contain confidential or<br>=0Aprivileged information. Unaut=
horized use of this communication is strictly<br>=0Aprohibited and may be u=
nlawful. If you have received this communication<br>=0Ain error, please imm=
ediately notify the sender by reply e-mail and destroy<br>=0Aall copies of =
the communication and any attachments.<br>=0A</font>=0A =0A</div><br>-----L=
a pi=C3=A8ce jointe associ=C3=A9e suit-----<br><br><div class=3D"plainMail"=
>_______________________________________________<br>lb-l mailing list<br><a=
 ymailto=3D"mailto:[email protected]" href=3D"/mc/[email protected]"=
>[email protected]</a><br><a href=3D"http://vegan.net/mailman/listinfo/lb-l" t=
arget=3D"_blank">http://vegan.net/mailman/listinfo/lb-l</a><br>Searchable A=
rchive: <a href=3D"http://vegan.net/lb/archive" target=3D"_blank">http://ve=
gan.net/lb/archive</a><br><a href=3D"http://lbdigest.com" target=3D"_blank"=
>http://lbdigest.com</a> Load Balancing Digest<br><a href=3D"http://lbwiki.=
com" target=3D"_blank">http://lbwiki.com</a> Load Balancing Wiki<br></div><=
/blockquote></td></tr></table><br>=0A=0A=0A=0A=0A      
--0-669102004-1266521296=:68702--


--===============0071420925==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
lb-l mailing list
[email protected]
http://vegan.net/mailman/listinfo/lb-l
Searchable Archive: http://vegan.net/lb/archive
http://lbdigest.com Load Balancing Digest
http://lbwiki.com Load Balancing Wiki

--===============0071420925==--