Re: SSL w/ PCI best practices

Kenneth Salchow <[email protected]> Thu, 18 Feb 2010 11:42:14 -0800
Newsgroups gmane.comp.programming.load-balancing.general
Message-ID <4B18A8F75A6384449755BC7784073E9360EF76ADD6@exch11.olympus.f5net.com>
--===============0599167355==
Content-Language: en-US
Content-Type: multipart/signed; protocol="application/x-pkcs7-signature";
	micalg=SHA1; boundary="----=_NextPart_000_0151_01CAB0A0.2DFA8850"

------=_NextPart_000_0151_01CAB0A0.2DFA8850
Content-Type: multipart/alternative;
	boundary="----=_NextPart_001_0152_01CAB0A0.2DFA8850"


------=_NextPart_001_0152_01CAB0A0.2DFA8850
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: 7bit

If you re-encrypt, the benefit is in the reduced cost of the client side
sever certs as you can use internally generated ones between the
load-balancer and the physical servers; you also can often use certificates
with less strength and increase the SSL ID life to prevent frequent
key-exchange, which will also provide some benefit to the actual server.
Since the encryption is terminated, the load-balancer can allow you to shoot
the traffic to more advanced inspection and security services (like a WAF)
before re-encrypting it and sending it back to the server.  For the same
reason, you can still apply many acceleration capabilities like
caching/compression/etc. on the Load-balancer, which can still provide
benefit to the overall transaction and a reduction of overhead on the
servers themselves.  Lastly, the load balancer is still providing basic TCP
optimization like request pipe-lining which can still improve backend server
performance.

 

I'd also like to point out that-while I am certainly not speaking on terms
of being a PCI expert-I know that historically, as long as the path between
the load-balancer and the physical server is within a secure zone, many
organizations have not actually re-encrypted the traffic.  This is entirely
based on the interpretation of the PCI standard, the architecture of your
environment and the amount of risk associated with doing it.  Again, I have
not been directly active within the PCI compliance world for some time and
have never gone through an actual audit.  Others on the list may have more
input/experience with whether or not re-encryption is or isn't an option.  I
can only speak from past experience.

 

But, if it is a mandate for your environment, hopefully I helped point out
some reasons why an ADC can still provide some significant benefit.

 

Good luck!

 


KJ (Ken) Salchow, Jr. | Manager, Technical Marketing


D 651.423.1133

M 612.868.1258

P 206.272.5555

F 206.272.5555

 <http://www.f5.com/> www.f5.com

 

 

From: [email protected] [mailto:[email protected]] On Behalf Of
Van Ceylon, David
Sent: Thursday, February 18, 2010 1:01 PM
To: 'Load Balancing Mailing List'
Subject: [load balancing] SSL w/ PCI best practices

 

Hello - 

 

I have a question regarding the use of SSL while trying to maintain PCI
compliance.  If a load balancer/SSL accelerator is handling SSL, what
advantage is that in terms of SSL offload if we must re-encrypt back to the
servers?  This essentially limits the load balancer to URI inspection and
distributing traffic.  There seems to be no advantage to handling Certs
(other than wildcard) or de-encryption.  Forgive my ignorance but I'm
looking for basic best practices in this situation.

 

Thanks!

 

David VanCeylon

 

 

  _____  

This communication is the property of Qwest and may contain confidential or
privileged information. Unauthorized use of this communication is strictly
prohibited and may be unlawful. If you have received this communication
in error, please immediately notify the sender by reply e-mail and destroy
all copies of the communication and any attachments.


------=_NextPart_001_0152_01CAB0A0.2DFA8850
Content-Type: text/html;
	charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" =
xmlns:o=3D"urn:schemas-microsoft-com:office:office" =
xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:x=3D"urn:schemas-microsoft-com:office:excel" =
xmlns:p=3D"urn:schemas-microsoft-com:office:powerpoint" =
xmlns:a=3D"urn:schemas-microsoft-com:office:access" =
xmlns:dt=3D"uuid:C2F41010-65B3-11d1-A29F-00AA00C14882" =
xmlns:s=3D"uuid:BDC6E3F0-6DA3-11d1-A2A3-00AA00C14882" =
xmlns:rs=3D"urn:schemas-microsoft-com:rowset" xmlns:z=3D"#RowsetSchema" =
xmlns:b=3D"urn:schemas-microsoft-com:office:publisher" =
xmlns:ss=3D"urn:schemas-microsoft-com:office:spreadsheet" =
xmlns:c=3D"urn:schemas-microsoft-com:office:component:spreadsheet" =
xmlns:odc=3D"urn:schemas-microsoft-com:office:odc" =
xmlns:oa=3D"urn:schemas-microsoft-com:office:activation" =
xmlns:html=3D"http://www.w3.org/TR/REC-html40" =
xmlns:q=3D"http://schemas.xmlsoap.org/soap/envelope/" =
xmlns:rtc=3D"http://microsoft.com/officenet/conferencing" =
xmlns:D=3D"DAV:" xmlns:Repl=3D"http://schemas.microsoft.com/repl/" =
xmlns:mt=3D"http://schemas.microsoft.com/sharepoint/soap/meetings/" =
xmlns:x2=3D"http://schemas.microsoft.com/office/excel/2003/xml" =
xmlns:ppda=3D"http://www.passport.com/NameSpace.xsd" =
xmlns:ois=3D"http://schemas.microsoft.com/sharepoint/soap/ois/" =
xmlns:dir=3D"http://schemas.microsoft.com/sharepoint/soap/directory/" =
xmlns:ds=3D"http://www.w3.org/2000/09/xmldsig#" =
xmlns:dsp=3D"http://schemas.microsoft.com/sharepoint/dsp" =
xmlns:udc=3D"http://schemas.microsoft.com/data/udc" =
xmlns:xsd=3D"http://www.w3.org/2001/XMLSchema" =
xmlns:sub=3D"http://schemas.microsoft.com/sharepoint/soap/2002/1/alerts/"=
 xmlns:ec=3D"http://www.w3.org/2001/04/xmlenc#" =
xmlns:sp=3D"http://schemas.microsoft.com/sharepoint/" =
xmlns:sps=3D"http://schemas.microsoft.com/sharepoint/soap/" =
xmlns:xsi=3D"http://www.w3.org/2001/XMLSchema-instance" =
xmlns:udcs=3D"http://schemas.microsoft.com/data/udc/soap" =
xmlns:udcxf=3D"http://schemas.microsoft.com/data/udc/xmlfile" =
xmlns:udcp2p=3D"http://schemas.microsoft.com/data/udc/parttopart" =
xmlns:wf=3D"http://schemas.microsoft.com/sharepoint/soap/workflow/" =
xmlns:dsss=3D"http://schemas.microsoft.com/office/2006/digsig-setup" =
xmlns:dssi=3D"http://schemas.microsoft.com/office/2006/digsig" =
xmlns:mdssi=3D"http://schemas.openxmlformats.org/package/2006/digital-sig=
nature" =
xmlns:mver=3D"http://schemas.openxmlformats.org/markup-compatibility/2006=
" xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" =
xmlns:mrels=3D"http://schemas.openxmlformats.org/package/2006/relationshi=
ps" xmlns:spwp=3D"http://microsoft.com/sharepoint/webpartpages" =
xmlns:ex12t=3D"http://schemas.microsoft.com/exchange/services/2006/types"=
 =
xmlns:ex12m=3D"http://schemas.microsoft.com/exchange/services/2006/messag=
es" =
xmlns:pptsl=3D"http://schemas.microsoft.com/sharepoint/soap/SlideLibrary/=
" =
xmlns:spsl=3D"http://microsoft.com/webservices/SharePointPortalServer/Pub=
lishedLinksService" xmlns:Z=3D"urn:schemas-microsoft-com:" =
xmlns:st=3D"&#1;" xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<meta http-equiv=3DContent-Type content=3D"text/html; =
charset=3Dus-ascii">
<meta name=3DGenerator content=3D"Microsoft Word 12 (filtered medium)">
<!--[if !mso]>
<style>
v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style>
<![endif]-->
<style>
<!--
 /* Font Definitions */
 @font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
 /* Style Definitions */
 p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:#606420;
	text-decoration:underline;}
span.EmailStyle17
	{mso-style-type:personal;
	font-family:"Arial","sans-serif";
	color:windowtext;}
span.EmailStyle18
	{mso-style-type:personal-reply;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page Section1
	{size:8.5in 11.0in;
	margin:1.0in 1.25in 1.0in 1.25in;}
div.Section1
	{page:Section1;}
-->
</style>
<!--[if gte mso 9]><xml>
 <o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
 <o:shapelayout v:ext=3D"edit">
  <o:idmap v:ext=3D"edit" data=3D"1" />
 </o:shapelayout></xml><![endif]-->
</head>

<body lang=3DEN-US link=3Dblue vlink=3D"#606420">

<div class=3DSection1>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>If you re-encrypt, the benefit is in the reduced cost of =
the client
side sever certs as you can use internally generated ones between the
load-balancer and the physical servers; you also can often use =
certificates
with less strength and increase the SSL ID life to prevent frequent
key-exchange, which will also provide some benefit to the actual =
server.&nbsp; Since
the encryption is terminated, the load-balancer can allow you to shoot =
the
traffic to more advanced inspection and security services (like a WAF) =
before
re-encrypting it and sending it back to the server.&nbsp; For the same =
reason,
you can still apply many acceleration capabilities like
caching/compression/etc. on the Load-balancer, which can still provide =
benefit
to the overall transaction and a reduction of overhead on the servers
themselves.&nbsp; Lastly, the load balancer is still providing basic TCP
optimization like request pipe-lining which can still improve backend =
server
performance.<o:p></o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p>&nbsp;</o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>I&#8217;d also like to point out that&#8212;while I am =
certainly
not speaking on terms of being a PCI expert&#8212;I know that =
historically, as
long as the path between the load-balancer and the physical server is =
within a
secure zone, many organizations have not actually re-encrypted the
traffic.&nbsp; This is entirely based on the interpretation of the PCI =
standard,
the architecture of your environment and the amount of risk associated =
with
doing it.&nbsp; Again, I have not been directly active within the PCI
compliance world for some time and have never gone through an actual
audit.&nbsp; Others on the list may have more input/experience with =
whether or
not re-encryption is or isn&#8217;t an option.&nbsp; I can only speak =
from past
experience.<o:p></o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p>&nbsp;</o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>But, if it is a mandate for your environment, hopefully I =
helped
point out some reasons why an ADC can still provide some significant =
benefit.<o:p></o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p>&nbsp;</o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>Good luck!<o:p></o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p>&nbsp;</o:p></span></p>

<div>

<table class=3DMsoNormalTable border=3D0 cellpadding=3D0 width=3D425 =
style=3D'width:318.75pt'>
 <tr>
  <td colspan=3D5 style=3D'padding:.75pt .75pt .75pt .75pt'>
  <p class=3DMsoNormal><b><span =
style=3D'font-size:10.0pt;font-family:"Arial","sans-serif";
  color:#1F497D'>KJ (Ken) Salchow, Jr.</span></b><span =
style=3D'font-size:10.0pt;
  font-family:"Arial","sans-serif";color:#1F497D'> | Manager, Technical
  Marketing</span><span =
style=3D'font-family:"Calibri","sans-serif";color:#1F497D'><o:p></o:p></s=
pan></p>
  </td>
 </tr>
 <tr style=3D'height:9.0pt'>
  <td width=3D84 style=3D'width:63.0pt;padding:.75pt .75pt .75pt =
.75pt;height:9.0pt'>
  <p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;
  line-height:9.0pt'><b><span =
style=3D'font-size:7.5pt;font-family:"Arial","sans-serif";
  color:#333333'>D 651.423.1133</span></b><span =
style=3D'color:#1F497D'><o:p></o:p></span></p>
  </td>
  <td width=3D84 style=3D'width:63.0pt;padding:.75pt .75pt .75pt =
.75pt;height:9.0pt'>
  <p class=3DMsoNormal style=3D'line-height:9.0pt'><b><span =
style=3D'font-size:7.5pt;
  font-family:"Arial","sans-serif";color:#333333'>M =
612.868.1258</span></b><span
  =
style=3D'font-family:"Calibri","sans-serif";color:#1F497D'><o:p></o:p></s=
pan></p>
  </td>
  <td width=3D84 style=3D'width:63.0pt;padding:.75pt .75pt .75pt =
.75pt;height:9.0pt'>
  <p class=3DMsoNormal style=3D'line-height:9.0pt'><b><span =
style=3D'font-size:7.5pt;
  font-family:"Arial","sans-serif";color:#333333'>P =
206.272.5555</span></b><span
  =
style=3D'font-family:"Calibri","sans-serif";color:#1F497D'><o:p></o:p></s=
pan></p>
  </td>
  <td width=3D84 style=3D'width:63.0pt;padding:.75pt .75pt .75pt =
.75pt;height:9.0pt'>
  <p class=3DMsoNormal style=3D'line-height:9.0pt'><b><span =
style=3D'font-size:7.5pt;
  font-family:"Arial","sans-serif";color:#333333'>F =
206.272.5555</span></b><span
  =
style=3D'font-family:"Calibri","sans-serif";color:#1F497D'><o:p></o:p></s=
pan></p>
  </td>
  <td width=3D69 style=3D'width:51.75pt;padding:.75pt .75pt .75pt =
.75pt;height:
  9.0pt'>
  <p class=3DMsoNormal style=3D'line-height:9.0pt'><b><span =
style=3D'font-size:7.5pt;
  font-family:"Arial","sans-serif";color:#333333'><a =
href=3D"http://www.f5.com/"><span
  style=3D'color:#333333'>www.f5.com</span></a></span></b><span =
style=3D'font-family:
  "Calibri","sans-serif";color:#1F497D'><o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p>&nbsp;</o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p>&nbsp;</o:p></span></p>

<div>

<div style=3D'border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt =
0in 0in 0in'>

<p class=3DMsoNormal style=3D'margin-left:.5in'><b><span =
style=3D'font-size:10.0pt;
font-family:"Tahoma","sans-serif"'>From:</span></b><span =
style=3D'font-size:10.0pt;
font-family:"Tahoma","sans-serif"'> [email protected]
[mailto:[email protected]] <b>On Behalf Of </b>Van Ceylon, =
David<br>
<b>Sent:</b> Thursday, February 18, 2010 1:01 PM<br>
<b>To:</b> 'Load Balancing Mailing List'<br>
<b>Subject:</b> [load balancing] SSL w/ PCI best =
practices<o:p></o:p></span></p>

</div>

</div>

<p class=3DMsoNormal style=3D'margin-left:.5in'><o:p>&nbsp;</o:p></p>

<p class=3DMsoNormal style=3D'margin-left:.5in'><span =
style=3D'font-size:10.0pt;
font-family:"Arial","sans-serif"'>Hello &#8211; <o:p></o:p></span></p>

<p class=3DMsoNormal style=3D'margin-left:.5in'><span =
style=3D'font-size:10.0pt;
font-family:"Arial","sans-serif"'><o:p>&nbsp;</o:p></span></p>

<p class=3DMsoNormal style=3D'margin-left:.5in'><span =
style=3D'font-size:10.0pt;
font-family:"Arial","sans-serif"'>I have a question regarding the use of =
SSL
while trying to maintain PCI compliance. &nbsp;If a load balancer/SSL
accelerator is handling SSL, what advantage is that in terms of SSL =
offload if
we must re-encrypt back to the servers?&nbsp; This essentially limits =
the load
balancer to URI inspection and distributing traffic.&nbsp; There seems =
to be no
advantage to handling Certs (other than wildcard) or de-encryption.
&nbsp;Forgive my ignorance but I&#8217;m looking for basic best =
practices in
this situation.<o:p></o:p></span></p>

<p class=3DMsoNormal style=3D'margin-left:.5in'><span =
style=3D'font-size:10.0pt;
font-family:"Arial","sans-serif"'><o:p>&nbsp;</o:p></span></p>

<p class=3DMsoNormal style=3D'margin-left:.5in'><span =
style=3D'font-size:10.0pt;
font-family:"Arial","sans-serif"'>Thanks!<o:p></o:p></span></p>

<p class=3DMsoNormal style=3D'margin-left:.5in'><span =
style=3D'font-size:10.0pt;
font-family:"Arial","sans-serif"'><o:p>&nbsp;</o:p></span></p>

<p class=3DMsoNormal style=3D'margin-left:.5in'><span =
style=3D'font-size:10.0pt;
font-family:"Arial","sans-serif"'>David VanCeylon</span><o:p></o:p></p>

<p class=3DMsoNormal style=3D'margin-left:.5in'><o:p>&nbsp;</o:p></p>

<p class=3DMsoNormal style=3D'margin-left:.5in'><o:p>&nbsp;</o:p></p>

<div class=3DMsoNormal align=3Dcenter =
style=3D'margin-left:.5in;text-align:center'>

<hr size=3D2 width=3D"100%" align=3Dcenter>

</div>

<p class=3DMsoNormal style=3D'margin-left:.5in'><span =
style=3D'font-size:7.5pt;
font-family:"Arial","sans-serif";color:gray'>This communication is the =
property
of Qwest and may contain confidential or<br>
privileged information. Unauthorized use of this communication is =
strictly<br>
prohibited and may be unlawful. If you have received this =
communication<br>
in error, please immediately notify the sender by reply e-mail and =
destroy<br>
all copies of the communication and any =
attachments.</span><o:p></o:p></p>

</div>

</div>

</body>

</html>

------=_NextPart_001_0152_01CAB0A0.2DFA8850--

------=_NextPart_000_0151_01CAB0A0.2DFA8850
Content-Type: application/x-pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIIzjCCAlYw
ggG/oAMCAQICEEgb315xx3HUwgzZMb1Lyl0wDQYJKoZIhvcNAQEFBQAwYjELMAkGA1UEBhMCWkEx
JTAjBgNVBAoTHFRoYXd0ZSBDb25zdWx0aW5nIChQdHkpIEx0ZC4xLDAqBgNVBAMTI1RoYXd0ZSBQ
ZXJzb25hbCBGcmVlbWFpbCBJc3N1aW5nIENBMB4XDTA5MDgyNjIzNTc1MloXDTEwMDgyNjIzNTc1
MlowQjEfMB0GA1UEAxMWVGhhd3RlIEZyZWVtYWlsIE1lbWJlcjEfMB0GCSqGSIb3DQEJARYQay5z
YWxjaG93QGY1LmNvbTCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAry5h0di1dpSX3iunEOj5
yhbkKQwF8+4MnRaGp5LhwITm+/2K977gkxd2FqBho+iC0sMCxbFDarMawqOITQuzoW/0VqcOyNrW
Zh/L6dRQOSFIjJAz4eGAtuohC5N8oRdV+l1Zb8UcOua11YBPcOLAgD94AOcALm0DFlwaTsQi8pcC
AwEAAaMtMCswGwYDVR0RBBQwEoEQay5zYWxjaG93QGY1LmNvbTAMBgNVHRMBAf8EAjAAMA0GCSqG
SIb3DQEBBQUAA4GBAJDs8XatGqIVTw6NkEdNOxwIaxbQI8JU8NZcGIc42DbX/TsUXR8CAdFJ640Q
pXke6ldn8I01pEPEIlUWri2zNrEVgSuHGizrt3qGn8hHU4hmO3vdhHqXWeowalRZMDA8P9oMAhjK
2j9EfnxJ8N5USl8/JEbayDFnjFvBU7DOi08PMIIDLTCCApagAwIBAgIBADANBgkqhkiG9w0BAQQF
ADCB0TELMAkGA1UEBhMCWkExFTATBgNVBAgTDFdlc3Rlcm4gQ2FwZTESMBAGA1UEBxMJQ2FwZSBU
b3duMRowGAYDVQQKExFUaGF3dGUgQ29uc3VsdGluZzEoMCYGA1UECxMfQ2VydGlmaWNhdGlvbiBT
ZXJ2aWNlcyBEaXZpc2lvbjEkMCIGA1UEAxMbVGhhd3RlIFBlcnNvbmFsIEZyZWVtYWlsIENBMSsw
KQYJKoZIhvcNAQkBFhxwZXJzb25hbC1mcmVlbWFpbEB0aGF3dGUuY29tMB4XDTk2MDEwMTAwMDAw
MFoXDTIwMTIzMTIzNTk1OVowgdExCzAJBgNVBAYTAlpBMRUwEwYDVQQIEwxXZXN0ZXJuIENhcGUx
EjAQBgNVBAcTCUNhcGUgVG93bjEaMBgGA1UEChMRVGhhd3RlIENvbnN1bHRpbmcxKDAmBgNVBAsT
H0NlcnRpZmljYXRpb24gU2VydmljZXMgRGl2aXNpb24xJDAiBgNVBAMTG1RoYXd0ZSBQZXJzb25h
bCBGcmVlbWFpbCBDQTErMCkGCSqGSIb3DQEJARYccGVyc29uYWwtZnJlZW1haWxAdGhhd3RlLmNv
bTCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA1GnX1LCUZFtx6UfYDFG26nKRsIRefS0Nj3sS
34UldSh0OkIsYyeflXtL734Zhx2G6qPduc6WZBrCFG5ErHzmj+hND3EfQDimAKOHePb5lIZererA
Xnbr2RSjXW56fAylS1V/Bhkpf56aJtVquzgkCGqYx7Hao5iR/Xnb5VrEHLkCAwEAAaMTMBEwDwYD
VR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQQFAAOBgQDH7JJ+Tvj1lqVnYiqk8E0RYNBvjWBYYawm
u1I1XAjPMPuoSpaKH2JCI4wXD/S6ZJwXrEcp352YXtJsYHFcoqzceePnbgBHH7UNKOgCneSa/RP0
ptl8sfjcXyMmCZGAc9AUG95DqYMl8uacLxXK/qarigd1iwzdUYRr5PjRzneigTCCAz8wggKooAMC
AQICAQ0wDQYJKoZIhvcNAQEFBQAwgdExCzAJBgNVBAYTAlpBMRUwEwYDVQQIEwxXZXN0ZXJuIENh
cGUxEjAQBgNVBAcTCUNhcGUgVG93bjEaMBgGA1UEChMRVGhhd3RlIENvbnN1bHRpbmcxKDAmBgNV
BAsTH0NlcnRpZmljYXRpb24gU2VydmljZXMgRGl2aXNpb24xJDAiBgNVBAMTG1RoYXd0ZSBQZXJz
b25hbCBGcmVlbWFpbCBDQTErMCkGCSqGSIb3DQEJARYccGVyc29uYWwtZnJlZW1haWxAdGhhd3Rl
LmNvbTAeFw0wMzA3MTcwMDAwMDBaFw0xMzA3MTYyMzU5NTlaMGIxCzAJBgNVBAYTAlpBMSUwIwYD
VQQKExxUaGF3dGUgQ29uc3VsdGluZyAoUHR5KSBMdGQuMSwwKgYDVQQDEyNUaGF3dGUgUGVyc29u
YWwgRnJlZW1haWwgSXNzdWluZyBDQTCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAxKY8VXNV
+065yplaHmjAdQRwnd/p/6Me7L3N9VvyGna9fww6YfK/Uc4B1OVQCjDXAmNaLIkVcI7dyfArhVqq
P3FWy688Cwfn8R+RNiQqE88r1fOCdz0Dviv+uxg+B79AgAJk16emu59l0cUqVIUPSAR/p7bRPGEE
QB5kGXJgt/sCAwEAAaOBlDCBkTASBgNVHRMBAf8ECDAGAQH/AgEAMEMGA1UdHwQ8MDowOKA2oDSG
Mmh0dHA6Ly9jcmwudGhhd3RlLmNvbS9UaGF3dGVQZXJzb25hbEZyZWVtYWlsQ0EuY3JsMAsGA1Ud
DwQEAwIBBjApBgNVHREEIjAgpB4wHDEaMBgGA1UEAxMRUHJpdmF0ZUxhYmVsMi0xMzgwDQYJKoZI
hvcNAQEFBQADgYEASIzRUIPqCy7MDaNmrGcPf6+svsIXoUOWlJ1/TCG4+DYfqi2fNi/A9BxQIJNw
PP2t4WFiw9k6GX6EsZkbAMUaC4J0niVQlGLH2ydxVyWN3amcOY6MIE9lX5Xa9/eH1sYITq726jTl
EBpbNU1341YheILcIRk13iSx0x1G/11fZU8xggL4MIIC9AIBATB2MGIxCzAJBgNVBAYTAlpBMSUw
IwYDVQQKExxUaGF3dGUgQ29uc3VsdGluZyAoUHR5KSBMdGQuMSwwKgYDVQQDEyNUaGF3dGUgUGVy
c29uYWwgRnJlZW1haWwgSXNzdWluZyBDQQIQSBvfXnHHcdTCDNkxvUvKXTAJBgUrDgMCGgUAoIIB
2DAYBgkqhkiG9w0BCQMxCwYJKoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xMDAyMTgxOTQyMTRa
MCMGCSqGSIb3DQEJBDEWBBTv2NyOMpb3QU9EHxnov8nJylNzXDBnBgkqhkiG9w0BCQ8xWjBYMAoG
CCqGSIb3DQMHMA4GCCqGSIb3DQMCAgIAgDANBggqhkiG9w0DAgIBQDAHBgUrDgMCBzANBggqhkiG
9w0DAgIBKDAHBgUrDgMCGjAKBggqhkiG9w0CBTCBhQYJKwYBBAGCNxAEMXgwdjBiMQswCQYDVQQG
EwJaQTElMCMGA1UEChMcVGhhd3RlIENvbnN1bHRpbmcgKFB0eSkgTHRkLjEsMCoGA1UEAxMjVGhh
d3RlIFBlcnNvbmFsIEZyZWVtYWlsIElzc3VpbmcgQ0ECEEgb315xx3HUwgzZMb1Lyl0wgYcGCyqG
SIb3DQEJEAILMXigdjBiMQswCQYDVQQGEwJaQTElMCMGA1UEChMcVGhhd3RlIENvbnN1bHRpbmcg
KFB0eSkgTHRkLjEsMCoGA1UEAxMjVGhhd3RlIFBlcnNvbmFsIEZyZWVtYWlsIElzc3VpbmcgQ0EC
EEgb315xx3HUwgzZMb1Lyl0wDQYJKoZIhvcNAQEBBQAEgYBdNtq/vRYv1yLEusqR/ww1tFGOmp3d
m0Eu6UzaBjnWIVKyC6UT1BmzHsNe1EP6ISJiQ6fukc0LuGe4LLNIWZ396QJIrzukmzaAqCVJ7Etp
mUN4G3U14kD4LDvtpWqWB83eShm+8J3JZRvPmsJdRmERlShh5FWeE8mBYWcvLTzoNwAAAAAAAA==

------=_NextPart_000_0151_01CAB0A0.2DFA8850--

--===============0599167355==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
lb-l mailing list
[email protected]
http://vegan.net/mailman/listinfo/lb-l
Searchable Archive: http://vegan.net/lb/archive
http://lbdigest.com Load Balancing Digest
http://lbwiki.com Load Balancing Wiki

--===============0599167355==--