Re: Re : SSL w/ PCI best practices
Tony Bourke <[email protected]> Thu, 18 Feb 2010 12:11:18 -0800
| Newsgroups | gmane.comp.programming.load-balancing.general |
|---|---|
| Message-ID | <[email protected]> |
This is a multi-part message in MIME format. --===============0183244638== Content-Type: multipart/alternative; boundary="------------010309040301080006050000" This is a multi-part message in MIME format. --------------010309040301080006050000 Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: quoted-printable X-MIME-Autoconverted: from 8bit to quoted-printable by soda.vegan.net id o1IKBKWQ016086 Something to keep in mind is that when last I checked (which was a bit=20 ago) many SSL providers do require you to purchase an additional=20 *license* for each server on the back end for a given cert, even if=20 you're using a self-signed cert behind the load balancer or not=20 re-encrypting. On a purely technical level, you only need one SSL=20 certificate, but on a licensing level, many CAs licenses require you=20 purchase an additional license for each server. Got three servers and a=20 pair of load balancers? You need to buy one cert and two additional=20 licenses. So be sure to check your SSL providers licenses. How this translates into VMs, Multi-cores, etc., I'm not sure. Tony On 2/18/2010 11:28 AM, Surya ARBY wrote: > Hello David. > > Some examples : > > - you can use self signed certificates on the server side, while you=20 > have only one public certificate on your SSL accelerator > > - you can leverage TCP reuse / http multiplexing / SSL reuse to reduce=20 > the number of SSL handshakes on the server side even if some entities=20 > on the client side do not support it. > > - using a SSL hardware card (only one) in the LB is far more scalable=20 > than processing all the SSL load in software on the servers (you can=20 > put SSL cards in the servers too but byuing SSL cards for each servers=20 > can become quite expensive :) ) > > - you can use different ciphers on the front end and the back end (for=20 > example : AES / sha1 on the client side, RC4+md5 on the server side)=20 > to reduce the load on the servers > > etc... > > regards, > > Surya > > --- En date de : *Jeu 18.2.10, Van Ceylon, David=20 > /<[email protected]>/* a =C3=A9crit : > > > De: Van Ceylon, David <[email protected]> > Objet: [load balancing] SSL w/ PCI best practices > =C3=80: "'Load Balancing Mailing List'" <[email protected]> > Date: Jeudi 18 f=C3=A9vrier 2010, 20h00 > > Hello =E2=80=93 > > I have a question regarding the use of SSL while trying to > maintain PCI compliance. If a load balancer/SSL accelerator is > handling SSL, what advantage is that in terms of SSL offload if we > must re-encrypt back to the servers? This essentially limits the > load balancer to URI inspection and distributing traffic. There > seems to be no advantage to handling Certs (other than wildcard) > or de-encryption. Forgive my ignorance but I=E2=80=99m looking for= basic > best practices in this situation. > > Thanks! > > David VanCeylon > > > -------------------------------------------------------------------= ----- > This communication is the property of Qwest and may contain > confidential or > privileged information. Unauthorized use of this communication is > strictly > prohibited and may be unlawful. If you have received this > communication > in error, please immediately notify the sender by reply e-mail and > destroy > all copies of the communication and any attachments. > > -----La pi=C3=A8ce jointe associ=C3=A9e suit----- > > _______________________________________________ > lb-l mailing list > [email protected] </mc/[email protected]> > http://vegan.net/mailman/listinfo/lb-l > Searchable Archive: http://vegan.net/lb/archive > http://lbdigest.com Load Balancing Digest > http://lbwiki.com Load Balancing Wiki > > > > _______________________________________________ > lb-l mailing list > [email protected] > http://vegan.net/mailman/listinfo/lb-l > Searchable Archive: http://vegan.net/lb/archive > http://lbdigest.com Load Balancing Digest > http://lbwiki.com Load Balancing Wiki > =20 --------------010309040301080006050000 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable X-MIME-Autoconverted: from 8bit to quoted-printable by soda.vegan.net id o1IKBKWQ016086 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html> <head> <meta content=3D"text/html; charset=3DUTF-8" http-equiv=3D"Content-Type= "> <title></title> </head> <body bgcolor=3D"#ffffff" text=3D"#000000"> Something to keep in mind is that when last I checked (which was a bit ago) many SSL providers do require you to purchase an additional *license* for each server on the back end for a given cert, even if you're using a self-signed cert behind the load balancer or not re-encrypting.=C2=A0 On a purely technical level, you only need one SSL certificate, but on a licensing level, many CAs licenses require you purchase an additional license for each server.=C2=A0 Got three servers a= nd a pair of load balancers?=C2=A0 You need to buy one cert and two addition= al licenses.=C2=A0=C2=A0 So be sure to check your SSL providers licenses. <b= r> <br> How this translates into VMs, Multi-cores, etc., I'm not sure. <br> <br> Tony<br> <br> =C2=A0=C2=A0 <br> <br> On 2/18/2010 11:28 AM, Surya ARBY wrote: <blockquote cite=3D"mid:[email protected]" type=3D"cite"> <table border=3D"0" cellpadding=3D"0" cellspacing=3D"0"> <tbody> <tr> <td style=3D"font-family: inherit; font-style: inherit; font-variant: inheri= t; font-weight: inherit; font-size: inherit; line-height: inherit; font-s= ize-adjust: inherit; font-stretch: inherit; -x-system-font: none;" valign=3D"top">Hello David.<br> <br> Some examples :<br> <br> - you can use self signed certificates on the server side, while you have only one public certificate on your SSL accelerator<br> <br> - you can leverage TCP reuse / http multiplexing / SSL reuse to reduce the number of SSL handshakes on the server side even if some entities on the client side do not support it.<br> <br> - using a SSL hardware card (only one) in the LB is far more scalable than processing all the SSL load in software on the servers (you can put SSL cards in the servers too but byuing SSL cards for each servers can become quite expensive :) )<br> <br> - you can use different ciphers on the front end and the back end (for example : AES / sha1 on the client side, RC4+md5 on the server side) to reduce the load on the servers<br> <br> etc...<br> <br> regards,<br> <br> Surya<br> <br> --- En date de=C2=A0: <b>Jeu 18.2.10, Van Ceylon, David <i><a class=3D"mo= z-txt-link-rfc2396E" href=3D"mailto:[email protected]"><David.= [email protected]></a></i></b> a =C3=A9crit=C2=A0:<br> <blockquote style=3D"border-left: 2px solid rgb(16, 16, 255); margin-left: 5px; padd= ing-left: 5px;"><br> De: Van Ceylon, David <a class=3D"moz-txt-link-rfc2396E" href=3D"mailto:D= [email protected]"><[email protected]></a><br> Objet: [load balancing] SSL w/ PCI best practices<br> =C3=80: "'Load Balancing Mailing List'" <a class=3D"moz-txt-link-rfc2396E= " href=3D"mailto:[email protected]"><[email protected]></a><br> Date: Jeudi 18 f=C3=A9vrier 2010, 20h00<br> <br> <div id=3D"yiv1752802633"> <style> <!-- #yiv1752802633 =20 #yiv1752802633 p.MsoNormal, #yiv1752802633 li.MsoNormal, #yiv1752802633 d= iv.MsoNormal {margin:0in;margin-bottom:.0001pt;font-size:12.0pt;font-family:"Times Ne= w Roman";} #yiv1752802633 a:link, #yiv1752802633 span.MsoHyperlink {color:blue;text-decoration:underline;} #yiv1752802633 a:visited, #yiv1752802633 span.MsoHyperlinkFollowed {color:#606420;text-decoration:underline;} #yiv1752802633 span.EmailStyle17 {font-family:Arial;color:windowtext;} _filtered #yiv1752802633 {margin:1.0in 1.25in 1.0in 1.25in;} #yiv1752802633 div.Section1 {} --> </style> <div class=3D"Section1"> <p class=3D"MsoNormal"><font face=3D"Arial" size=3D"2"><span style=3D"font-size: 10pt; font-family: Arial;">Hello =E2=80=93 </span></font></p> <p class=3D"MsoNormal"><font face=3D"Arial" size=3D"2"><span style=3D"font-size: 10pt; font-family: Arial;"> =C2=A0</span></font></p> <p class=3D"MsoNormal"><font face=3D"Arial" size=3D"2"><span style=3D"font-size: 10pt; font-family: Arial;">I have a question regarding the use of SSL while trying to maintain PCI compliance. =C2=A0I= f a load balancer/SSL accelerator is handling SSL, what advantage is that in terms of SSL offload if we must re-encrypt back to the servers?=C2=A0 This essentially limits the load balancer to URI inspection and distributing traffic.=C2=A0 There seems to be no advantage to handling Ce= rts (other than wildcard) or de-encryption. =C2=A0Forgive my ignorance but I=E2= =80=99m looking for basic best practices in this situation.</span></font></p> <p class=3D"MsoNormal"><font face=3D"Arial" size=3D"2"><span style=3D"font-size: 10pt; font-family: Arial;"> =C2=A0</span></font></p> <p class=3D"MsoNormal"><font face=3D"Arial" size=3D"2"><span style=3D"font-size: 10pt; font-family: Arial;">Thanks!</span></font></p> <p class=3D"MsoNormal"><font face=3D"Arial" size=3D"2"><span style=3D"font-size: 10pt; font-family: Arial;"> =C2=A0</span></font></p> <p class=3D"MsoNormal"><font face=3D"Arial" size=3D"2"><span style=3D"font-size: 10pt; font-family: Arial;">David VanCeylon</span></f= ont></p> <p class=3D"MsoNormal"><font face=3D"Times New Roman" size=3D"3= "><span style=3D"font-size: 12pt;"> =C2=A0</span></font></p> </div> <br> <hr> <font color=3D"Gray" face=3D"Arial" size=3D"1">This communicati= on is the property of Qwest and may contain confidential or<br> privileged information. Unauthorized use of this communication is strictly<br> prohibited and may be unlawful. If you have received this communication<b= r> in error, please immediately notify the sender by reply e-mail and destroy<br> all copies of the communication and any attachments.<br> </font> </div> <br> -----La pi=C3=A8ce jointe associ=C3=A9e suit-----<br> <br> <div class=3D"plainMail">______________________________________= _________<br> lb-l mailing list<br> <a moz-do-not-send=3D"true" ymailto=3D"mailto:[email protected]" href=3D"/mc/[email protected]">[email protected]</a><br> <a moz-do-not-send=3D"true" href=3D"http://vegan.net/mailman/listinfo/lb-l" target=3D"_blank">http:/= /vegan.net/mailman/listinfo/lb-l</a><br> Searchable Archive: <a moz-do-not-send=3D"true" href=3D"http://vegan.net/lb/archive" target=3D"_blank">http://vegan.net/= lb/archive</a><br> <a moz-do-not-send=3D"true" href=3D"http://lbdigest.com" target=3D"_blank">http://lbdigest.com</a> Load Balancing Digest<br> <a moz-do-not-send=3D"true" href=3D"http://lbwiki.com" target=3D"_blank">http://lbwiki.com</a> Load Balancing Wiki<br> </div> </blockquote> </td> </tr> </tbody> </table> <br> <pre wrap=3D""> <fieldset class=3D"mimeAttachmentHeader"></fieldset> _______________________________________________ lb-l mailing list <a class=3D"moz-txt-link-abbreviated" href=3D"mailto:[email protected]">lb-l= @vegan.net</a> <a class=3D"moz-txt-link-freetext" href=3D"http://vegan.net/mailman/listi= nfo/lb-l">http://vegan.net/mailman/listinfo/lb-l</a> Searchable Archive: <a class=3D"moz-txt-link-freetext" href=3D"http://veg= an.net/lb/archive">http://vegan.net/lb/archive</a> <a class=3D"moz-txt-link-freetext" href=3D"http://lbdigest.com">http://lb= digest.com</a> Load Balancing Digest <a class=3D"moz-txt-link-freetext" href=3D"http://lbwiki.com">http://lbwi= ki.com</a> Load Balancing Wiki </pre> </blockquote> <br> </body> </html> --------------010309040301080006050000-- --===============0183244638== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Disposition: inline Content-Transfer-Encoding: 7bit _______________________________________________ lb-l mailing list [email protected] http://vegan.net/mailman/listinfo/lb-l Searchable Archive: http://vegan.net/lb/archive http://lbdigest.com Load Balancing Digest http://lbwiki.com Load Balancing Wiki --===============0183244638==--