Re: Re : SSL w/ PCI best practices

Kenneth Salchow <[email protected]> Thu, 18 Feb 2010 12:56:03 -0800
Newsgroups gmane.comp.programming.load-balancing.general
Message-ID <4B18A8F75A6384449755BC7784073E9360EF81FFC6@exch11.olympus.f5net.com>
--===============0426857873==
Content-Language: en-US
Content-Type: multipart/signed; protocol="application/x-pkcs7-signature";
	micalg=SHA1; boundary="----=_NextPart_000_0008_01CAB0AA.7C782D20"

------=_NextPart_000_0008_01CAB0AA.7C782D20
Content-Type: multipart/alternative;
	boundary="----=_NextPart_001_0009_01CAB0AA.7C782D20"


------=_NextPart_001_0009_01CAB0AA.7C782D20
Content-Type: text/plain;
	charset="utf-8"
Content-Transfer-Encoding: quoted-printable

Good point Tony=E2=80=94don=E2=80=99t want to upset the global CA gods =
do we? J

=20


KJ (Ken) Salchow, Jr. | Manager, Technical Marketing


D 651.423.1133

M 612.868.1258

P 206.272.5555

F 206.272.5555

 <http://www.f5.com/> www.f5.com

=20

=20

From: [email protected] [mailto:[email protected]] On Behalf =
Of Tony Bourke
Sent: Thursday, February 18, 2010 2:11 PM
To: [email protected]
Subject: Re: [load balancing] Re : SSL w/ PCI best practices

=20

Something to keep in mind is that when last I checked (which was a bit =
ago) many SSL providers do require you to purchase an additional =
*license* for each server on the back end for a given cert, even if =
you're using a self-signed cert behind the load balancer or not =
re-encrypting.  On a purely technical level, you only need one SSL =
certificate, but on a licensing level, many CAs licenses require you =
purchase an additional license for each server.  Got three servers and a =
pair of load balancers?  You need to buy one cert and two additional =
licenses.   So be sure to check your SSL providers licenses.=20

How this translates into VMs, Multi-cores, etc., I'm not sure.=20

Tony

  =20

On 2/18/2010 11:28 AM, Surya ARBY wrote:=20


Hello David.

Some examples :

- you can use self signed certificates on the server side, while you =
have only one public certificate on your SSL accelerator

- you can leverage TCP reuse / http multiplexing / SSL reuse to reduce =
the number of SSL handshakes on the server side even if some entities on =
the client side do not support it.

- using a SSL hardware card (only one) in the LB is far more scalable =
than processing all the SSL load in software on the servers (you can put =
SSL cards in the servers too but byuing SSL cards for each servers can =
become quite expensive :) )

- you can use different ciphers on the front end and the back end (for =
example : AES / sha1 on the client side, RC4+md5 on the server side) to =
reduce the load on the servers

etc...

regards,

Surya

--- En date de : Jeu 18.2.10, Van Ceylon, David  =
<mailto:[email protected]> <[email protected]> a =
=C3=A9crit :


De: Van Ceylon, David  <mailto:[email protected]> =
<[email protected]>
Objet: [load balancing] SSL w/ PCI best practices
=C3=80: "'Load Balancing Mailing List'"  <mailto:[email protected]> =
<[email protected]>
Date: Jeudi 18 f=C3=A9vrier 2010, 20h00

Hello =E2=80=93=20

=20

I have a question regarding the use of SSL while trying to maintain PCI =
compliance.  If a load balancer/SSL accelerator is handling SSL, what =
advantage is that in terms of SSL offload if we must re-encrypt back to =
the servers?  This essentially limits the load balancer to URI =
inspection and distributing traffic.  There seems to be no advantage to =
handling Certs (other than wildcard) or de-encryption.  Forgive my =
ignorance but I=E2=80=99m looking for basic best practices in this =
situation.

=20

Thanks!

=20

David VanCeylon

=20

=20

  _____ =20

This communication is the property of Qwest and may contain confidential =
or
privileged information. Unauthorized use of this communication is =
strictly
prohibited and may be unlawful. If you have received this communication
in error, please immediately notify the sender by reply e-mail and =
destroy
all copies of the communication and any attachments.


-----La pi=C3=A8ce jointe associ=C3=A9e suit-----

_______________________________________________
lb-l mailing list
[email protected]
http://vegan.net/mailman/listinfo/lb-l
Searchable Archive: http://vegan.net/lb/archive
http://lbdigest.com Load Balancing Digest
http://lbwiki.com Load Balancing Wiki





=20
=20
_______________________________________________
lb-l mailing list
[email protected]
http://vegan.net/mailman/listinfo/lb-l
Searchable Archive: http://vegan.net/lb/archive
http://lbdigest.com Load Balancing Digest
http://lbwiki.com Load Balancing Wiki
 =20

=20


------=_NextPart_001_0009_01CAB0AA.7C782D20
Content-Type: text/html;
	charset="utf-8"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" =
xmlns:o=3D"urn:schemas-microsoft-com:office:office" =
xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" =
xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<meta http-equiv=3DContent-Type content=3D"text/html; charset=3Dutf-8">
<meta name=3DGenerator content=3D"Microsoft Word 12 (filtered medium)">
<!--[if !mso]>
<style>
v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style>
<![endif]-->
<style>
<!--
 /* Font Definitions */
 @font-face
	{font-family:Wingdings;
	panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
	{font-family:Wingdings;
	panose-1:5 0 0 0 0 0 0 0 0 0;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
@font-face
	{font-family:inherit;
	panose-1:0 0 0 0 0 0 0 0 0 0;}
@font-face
	{font-family:Consolas;
	panose-1:2 11 6 9 2 2 4 3 2 4;}
 /* Style Definitions */
 p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";
	color:black;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
pre
	{mso-style-priority:99;
	mso-style-link:"HTML Preformatted Char";
	margin:0in;
	margin-bottom:.0001pt;
	font-size:10.0pt;
	font-family:"Courier New";
	color:black;}
span.emailstyle17
	{mso-style-name:emailstyle17;}
span.emailstyle171
	{mso-style-name:emailstyle171;
	font-family:"Arial","sans-serif";
	color:windowtext;}
span.HTMLPreformattedChar
	{mso-style-name:"HTML Preformatted Char";
	mso-style-priority:99;
	mso-style-link:"HTML Preformatted";
	font-family:Consolas;
	color:black;}
span.EmailStyle21
	{mso-style-type:personal-reply;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page Section1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.Section1
	{page:Section1;}
-->
</style>
<!--[if gte mso 9]><xml>
 <o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
 <o:shapelayout v:ext=3D"edit">
  <o:idmap v:ext=3D"edit" data=3D"1" />
 </o:shapelayout></xml><![endif]-->
</head>

<body bgcolor=3Dwhite lang=3DEN-US link=3Dblue vlink=3D"#000000">

<div class=3DSection1>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>Good point Tony=E2=80=94don=E2=80=99t want to upset the =
global CA gods do we? </span><span
style=3D'font-size:11.0pt;font-family:Wingdings;color:#1F497D'>J</span><s=
pan
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'><o:p></o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p>&nbsp;</o:p></span></p>

<div>

<table class=3DMsoNormalTable border=3D0 cellpadding=3D0 width=3D425 =
style=3D'width:318.75pt'>
 <tr>
  <td colspan=3D5 style=3D'padding:.75pt .75pt .75pt .75pt'>
  <p class=3DMsoNormal><b><span =
style=3D'font-size:10.0pt;font-family:"Arial","sans-serif";
  color:#1F497D'>KJ (Ken) Salchow, Jr.</span></b><span =
style=3D'font-size:10.0pt;
  font-family:"Arial","sans-serif";color:#1F497D'> | Manager, Technical
  Marketing</span><span =
style=3D'font-family:"Calibri","sans-serif";color:#1F497D'><o:p></o:p></s=
pan></p>
  </td>
 </tr>
 <tr style=3D'height:9.0pt'>
  <td width=3D84 style=3D'width:63.0pt;padding:.75pt .75pt .75pt =
.75pt;height:9.0pt'>
  <p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;
  line-height:9.0pt'><b><span =
style=3D'font-size:7.5pt;font-family:"Arial","sans-serif";
  color:#333333'>D 651.423.1133</span></b><span =
style=3D'color:#1F497D'><o:p></o:p></span></p>
  </td>
  <td width=3D84 style=3D'width:63.0pt;padding:.75pt .75pt .75pt =
.75pt;height:9.0pt'>
  <p class=3DMsoNormal style=3D'line-height:9.0pt'><b><span =
style=3D'font-size:7.5pt;
  font-family:"Arial","sans-serif";color:#333333'>M =
612.868.1258</span></b><span
  =
style=3D'font-family:"Calibri","sans-serif";color:#1F497D'><o:p></o:p></s=
pan></p>
  </td>
  <td width=3D84 style=3D'width:63.0pt;padding:.75pt .75pt .75pt =
.75pt;height:9.0pt'>
  <p class=3DMsoNormal style=3D'line-height:9.0pt'><b><span =
style=3D'font-size:7.5pt;
  font-family:"Arial","sans-serif";color:#333333'>P =
206.272.5555</span></b><span
  =
style=3D'font-family:"Calibri","sans-serif";color:#1F497D'><o:p></o:p></s=
pan></p>
  </td>
  <td width=3D84 style=3D'width:63.0pt;padding:.75pt .75pt .75pt =
.75pt;height:9.0pt'>
  <p class=3DMsoNormal style=3D'line-height:9.0pt'><b><span =
style=3D'font-size:7.5pt;
  font-family:"Arial","sans-serif";color:#333333'>F =
206.272.5555</span></b><span
  =
style=3D'font-family:"Calibri","sans-serif";color:#1F497D'><o:p></o:p></s=
pan></p>
  </td>
  <td width=3D69 style=3D'width:51.75pt;padding:.75pt .75pt .75pt =
.75pt;height:
  9.0pt'>
  <p class=3DMsoNormal style=3D'line-height:9.0pt'><b><span =
style=3D'font-size:7.5pt;
  font-family:"Arial","sans-serif";color:#333333'><a =
href=3D"http://www.f5.com/"><span
  style=3D'color:#333333'>www.f5.com</span></a></span></b><span =
style=3D'font-family:
  "Calibri","sans-serif";color:#1F497D'><o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p>&nbsp;</o:p></span></p>

</div>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p>&nbsp;</o:p></span></p>

<div>

<div style=3D'border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt =
0in 0in 0in'>

<p class=3DMsoNormal style=3D'margin-left:.5in'><b><span =
style=3D'font-size:10.0pt;
font-family:"Tahoma","sans-serif";color:windowtext'>From:</span></b><span=

style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif";color:windowt=
ext'>
[email protected] [mailto:[email protected]] <b>On Behalf Of =
</b>Tony
Bourke<br>
<b>Sent:</b> Thursday, February 18, 2010 2:11 PM<br>
<b>To:</b> [email protected]<br>
<b>Subject:</b> Re: [load balancing] Re : SSL w/ PCI best =
practices<o:p></o:p></span></p>

</div>

</div>

<p class=3DMsoNormal style=3D'margin-left:.5in'><o:p>&nbsp;</o:p></p>

<p class=3DMsoNormal style=3D'margin-left:.5in'>Something to keep in =
mind is that
when last I checked (which was a bit ago) many SSL providers do require =
you to
purchase an additional *license* for each server on the back end for a =
given
cert, even if you're using a self-signed cert behind the load balancer =
or not
re-encrypting.&nbsp; On a purely technical level, you only need one SSL
certificate, but on a licensing level, many CAs licenses require you =
purchase
an additional license for each server.&nbsp; Got three servers and a =
pair of
load balancers?&nbsp; You need to buy one cert and two additional
licenses.&nbsp;&nbsp; So be sure to check your SSL providers licenses. =
<br>
<br>
How this translates into VMs, Multi-cores, etc., I'm not sure. <br>
<br>
Tony<br>
<br>
&nbsp;&nbsp; <br>
<br>
On 2/18/2010 11:28 AM, Surya ARBY wrote: <o:p></o:p></p>

<table class=3DMsoNormalTable border=3D0 cellspacing=3D0 cellpadding=3D0 =
width=3D624
 style=3D'width:6.5in;margin-left:.5in'>
 <tr>
  <td valign=3Dtop style=3D'padding:0in 0in 0in =
0in;font-style:inherit;font-variant:
  =
inherit;font-weight:inherit;font-size:inherit;line-height:inherit;font-si=
ze-adjust: inherit;
  font-stretch: inherit;-x-system-font: none'>
  <p class=3DMsoNormal><span =
style=3D'font-family:"inherit","serif"'>Hello David.<br>
  <br>
  Some examples :<br>
  <br>
  - you can use self signed certificates on the server side, while you =
have
  only one public certificate on your SSL accelerator<br>
  <br>
  - you can leverage TCP reuse / http multiplexing / SSL reuse to reduce =
the
  number of SSL handshakes on the server side even if some entities on =
the
  client side do not support it.<br>
  <br>
  - using a SSL hardware card (only one) in the LB is far more scalable =
than
  processing all the SSL load in software on the servers (you can put =
SSL cards
  in the servers too but byuing SSL cards for each servers can become =
quite
  expensive :) )<br>
  <br>
  - you can use different ciphers on the front end and the back end (for
  example : AES / sha1 on the client side, RC4+md5 on the server side) =
to
  reduce the load on the servers<br>
  <br>
  etc...<br>
  <br>
  regards,<br>
  <br>
  Surya<br>
  <br>
  --- En date de&nbsp;: <b>Jeu 18.2.10, Van Ceylon, David <i><a
  =
href=3D"mailto:[email protected]">&lt;[email protected]&g=
t;</a></i></b>
  a =C3=A9crit&nbsp;:<o:p></o:p></span></p>
  <p class=3DMsoNormal style=3D'margin-bottom:12.0pt'><span =
style=3D'font-family:
  "inherit","serif"'><br>
  De: Van Ceylon, David <a =
href=3D"mailto:[email protected]">&lt;[email protected]&g=
t;</a><br>
  Objet: [load balancing] SSL w/ PCI best practices<br>
  =C3=80: &quot;'Load Balancing Mailing List'&quot; <a =
href=3D"mailto:[email protected]">&lt;[email protected]&gt;</a><br>
  Date: Jeudi 18 f=C3=A9vrier 2010, 20h00<o:p></o:p></span></p>
  <div id=3Dyiv1752802633>
  <div>
  <p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'><span
  style=3D'font-size:10.0pt;font-family:"Arial","sans-serif"'>Hello =
=E2=80=93 </span><o:p></o:p></p>
  <p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'><span
  =
style=3D'font-size:10.0pt;font-family:"Arial","sans-serif"'>&nbsp;</span>=
<o:p></o:p></p>
  <p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'><span
  style=3D'font-size:10.0pt;font-family:"Arial","sans-serif"'>I have a =
question
  regarding the use of SSL while trying to maintain PCI compliance. =
&nbsp;If a
  load balancer/SSL accelerator is handling SSL, what advantage is that =
in
  terms of SSL offload if we must re-encrypt back to the servers?&nbsp; =
This
  essentially limits the load balancer to URI inspection and =
distributing
  traffic.&nbsp; There seems to be no advantage to handling Certs (other =
than
  wildcard) or de-encryption. &nbsp;Forgive my ignorance but I=E2=80=99m =
looking for
  basic best practices in this situation.</span><o:p></o:p></p>
  <p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'><span
  =
style=3D'font-size:10.0pt;font-family:"Arial","sans-serif"'>&nbsp;</span>=
<o:p></o:p></p>
  <p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'><span
  =
style=3D'font-size:10.0pt;font-family:"Arial","sans-serif"'>Thanks!</span=
><o:p></o:p></p>
  <p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'><span
  =
style=3D'font-size:10.0pt;font-family:"Arial","sans-serif"'>&nbsp;</span>=
<o:p></o:p></p>
  <p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'><span
  style=3D'font-size:10.0pt;font-family:"Arial","sans-serif"'>David =
VanCeylon</span><o:p></o:p></p>
  <p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'>&nbsp;<o:p><=
/o:p></p>
  </div>
  <p class=3DMsoNormal><span =
style=3D'font-family:"inherit","serif"'><o:p>&nbsp;</o:p></span></p>
  <div class=3DMsoNormal align=3Dcenter =
style=3D'text-align:center'><span
  style=3D'font-family:"inherit","serif"'>
  <hr size=3D2 width=3D"100%" align=3Dcenter>
  </span></div>
  <p class=3DMsoNormal><span =
style=3D'font-size:7.5pt;font-family:"Arial","sans-serif";
  color:gray'>This communication is the property of Qwest and may =
contain confidential
  or<br>
  privileged information. Unauthorized use of this communication is =
strictly<br>
  prohibited and may be unlawful. If you have received this =
communication<br>
  in error, please immediately notify the sender by reply e-mail and =
destroy<br>
  all copies of the communication and any attachments.</span><span
  style=3D'font-family:"inherit","serif"'><o:p></o:p></span></p>
  </div>
  <p class=3DMsoNormal style=3D'margin-bottom:12.0pt'><span =
style=3D'font-family:
  "inherit","serif"'><br>
  -----La pi=C3=A8ce jointe associ=C3=A9e =
suit-----<o:p></o:p></span></p>
  <div>
  <p class=3DMsoNormal><span =
style=3D'font-family:"inherit","serif"'>_________________________________=
______________<br>
  lb-l mailing list<br>
  <a href=3D"/mc/[email protected]">[email protected]</a><br>
  <a href=3D"http://vegan.net/mailman/listinfo/lb-l" =
target=3D"_blank">http://vegan.net/mailman/listinfo/lb-l</a><br>
  Searchable Archive: <a href=3D"http://vegan.net/lb/archive" =
target=3D"_blank">http://vegan.net/lb/archive</a><br>
  <a href=3D"http://lbdigest.com" =
target=3D"_blank">http://lbdigest.com</a> Load
  Balancing Digest<br>
  <a href=3D"http://lbwiki.com" target=3D"_blank">http://lbwiki.com</a> =
Load
  Balancing Wiki<o:p></o:p></span></p>
  </div>
  </td>
 </tr>
</table>

<p class=3DMsoNormal style=3D'margin-left:.5in'><br>
<br>
<o:p></o:p></p>

<pre style=3D'margin-left:.5in'><o:p>&nbsp;</o:p></pre><pre =
style=3D'margin-left:
.5in'><o:p>&nbsp;</o:p></pre><pre =
style=3D'margin-left:.5in'>______________________________________________=
_<o:p></o:p></pre><pre
style=3D'margin-left:.5in'>lb-l mailing list<o:p></o:p></pre><pre
style=3D'margin-left:.5in'><a =
href=3D"mailto:[email protected]">[email protected]</a><o:p></o:p></pre><pre
style=3D'margin-left:.5in'><a =
href=3D"http://vegan.net/mailman/listinfo/lb-l">http://vegan.net/mailman/=
listinfo/lb-l</a><o:p></o:p></pre><pre
style=3D'margin-left:.5in'>Searchable Archive: <a
href=3D"http://vegan.net/lb/archive">http://vegan.net/lb/archive</a><o:p>=
</o:p></pre><pre
style=3D'margin-left:.5in'><a =
href=3D"http://lbdigest.com">http://lbdigest.com</a> Load Balancing =
Digest<o:p></o:p></pre><pre
style=3D'margin-left:.5in'><a =
href=3D"http://lbwiki.com">http://lbwiki.com</a> Load Balancing =
Wiki<o:p></o:p></pre><pre
style=3D'margin-left:.5in'>=C2=A0 <o:p></o:p></pre>

<p class=3DMsoNormal style=3D'margin-left:.5in'><o:p>&nbsp;</o:p></p>

</div>

</body>

</html>

------=_NextPart_001_0009_01CAB0AA.7C782D20--

------=_NextPart_000_0008_01CAB0AA.7C782D20
Content-Type: application/x-pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIIzjCCAlYw
ggG/oAMCAQICEEgb315xx3HUwgzZMb1Lyl0wDQYJKoZIhvcNAQEFBQAwYjELMAkGA1UEBhMCWkEx
JTAjBgNVBAoTHFRoYXd0ZSBDb25zdWx0aW5nIChQdHkpIEx0ZC4xLDAqBgNVBAMTI1RoYXd0ZSBQ
ZXJzb25hbCBGcmVlbWFpbCBJc3N1aW5nIENBMB4XDTA5MDgyNjIzNTc1MloXDTEwMDgyNjIzNTc1
MlowQjEfMB0GA1UEAxMWVGhhd3RlIEZyZWVtYWlsIE1lbWJlcjEfMB0GCSqGSIb3DQEJARYQay5z
YWxjaG93QGY1LmNvbTCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAry5h0di1dpSX3iunEOj5
yhbkKQwF8+4MnRaGp5LhwITm+/2K977gkxd2FqBho+iC0sMCxbFDarMawqOITQuzoW/0VqcOyNrW
Zh/L6dRQOSFIjJAz4eGAtuohC5N8oRdV+l1Zb8UcOua11YBPcOLAgD94AOcALm0DFlwaTsQi8pcC
AwEAAaMtMCswGwYDVR0RBBQwEoEQay5zYWxjaG93QGY1LmNvbTAMBgNVHRMBAf8EAjAAMA0GCSqG
SIb3DQEBBQUAA4GBAJDs8XatGqIVTw6NkEdNOxwIaxbQI8JU8NZcGIc42DbX/TsUXR8CAdFJ640Q
pXke6ldn8I01pEPEIlUWri2zNrEVgSuHGizrt3qGn8hHU4hmO3vdhHqXWeowalRZMDA8P9oMAhjK
2j9EfnxJ8N5USl8/JEbayDFnjFvBU7DOi08PMIIDLTCCApagAwIBAgIBADANBgkqhkiG9w0BAQQF
ADCB0TELMAkGA1UEBhMCWkExFTATBgNVBAgTDFdlc3Rlcm4gQ2FwZTESMBAGA1UEBxMJQ2FwZSBU
b3duMRowGAYDVQQKExFUaGF3dGUgQ29uc3VsdGluZzEoMCYGA1UECxMfQ2VydGlmaWNhdGlvbiBT
ZXJ2aWNlcyBEaXZpc2lvbjEkMCIGA1UEAxMbVGhhd3RlIFBlcnNvbmFsIEZyZWVtYWlsIENBMSsw
KQYJKoZIhvcNAQkBFhxwZXJzb25hbC1mcmVlbWFpbEB0aGF3dGUuY29tMB4XDTk2MDEwMTAwMDAw
MFoXDTIwMTIzMTIzNTk1OVowgdExCzAJBgNVBAYTAlpBMRUwEwYDVQQIEwxXZXN0ZXJuIENhcGUx
EjAQBgNVBAcTCUNhcGUgVG93bjEaMBgGA1UEChMRVGhhd3RlIENvbnN1bHRpbmcxKDAmBgNVBAsT
H0NlcnRpZmljYXRpb24gU2VydmljZXMgRGl2aXNpb24xJDAiBgNVBAMTG1RoYXd0ZSBQZXJzb25h
bCBGcmVlbWFpbCBDQTErMCkGCSqGSIb3DQEJARYccGVyc29uYWwtZnJlZW1haWxAdGhhd3RlLmNv
bTCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA1GnX1LCUZFtx6UfYDFG26nKRsIRefS0Nj3sS
34UldSh0OkIsYyeflXtL734Zhx2G6qPduc6WZBrCFG5ErHzmj+hND3EfQDimAKOHePb5lIZererA
Xnbr2RSjXW56fAylS1V/Bhkpf56aJtVquzgkCGqYx7Hao5iR/Xnb5VrEHLkCAwEAAaMTMBEwDwYD
VR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQQFAAOBgQDH7JJ+Tvj1lqVnYiqk8E0RYNBvjWBYYawm
u1I1XAjPMPuoSpaKH2JCI4wXD/S6ZJwXrEcp352YXtJsYHFcoqzceePnbgBHH7UNKOgCneSa/RP0
ptl8sfjcXyMmCZGAc9AUG95DqYMl8uacLxXK/qarigd1iwzdUYRr5PjRzneigTCCAz8wggKooAMC
AQICAQ0wDQYJKoZIhvcNAQEFBQAwgdExCzAJBgNVBAYTAlpBMRUwEwYDVQQIEwxXZXN0ZXJuIENh
cGUxEjAQBgNVBAcTCUNhcGUgVG93bjEaMBgGA1UEChMRVGhhd3RlIENvbnN1bHRpbmcxKDAmBgNV
BAsTH0NlcnRpZmljYXRpb24gU2VydmljZXMgRGl2aXNpb24xJDAiBgNVBAMTG1RoYXd0ZSBQZXJz
b25hbCBGcmVlbWFpbCBDQTErMCkGCSqGSIb3DQEJARYccGVyc29uYWwtZnJlZW1haWxAdGhhd3Rl
LmNvbTAeFw0wMzA3MTcwMDAwMDBaFw0xMzA3MTYyMzU5NTlaMGIxCzAJBgNVBAYTAlpBMSUwIwYD
VQQKExxUaGF3dGUgQ29uc3VsdGluZyAoUHR5KSBMdGQuMSwwKgYDVQQDEyNUaGF3dGUgUGVyc29u
YWwgRnJlZW1haWwgSXNzdWluZyBDQTCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAxKY8VXNV
+065yplaHmjAdQRwnd/p/6Me7L3N9VvyGna9fww6YfK/Uc4B1OVQCjDXAmNaLIkVcI7dyfArhVqq
P3FWy688Cwfn8R+RNiQqE88r1fOCdz0Dviv+uxg+B79AgAJk16emu59l0cUqVIUPSAR/p7bRPGEE
QB5kGXJgt/sCAwEAAaOBlDCBkTASBgNVHRMBAf8ECDAGAQH/AgEAMEMGA1UdHwQ8MDowOKA2oDSG
Mmh0dHA6Ly9jcmwudGhhd3RlLmNvbS9UaGF3dGVQZXJzb25hbEZyZWVtYWlsQ0EuY3JsMAsGA1Ud
DwQEAwIBBjApBgNVHREEIjAgpB4wHDEaMBgGA1UEAxMRUHJpdmF0ZUxhYmVsMi0xMzgwDQYJKoZI
hvcNAQEFBQADgYEASIzRUIPqCy7MDaNmrGcPf6+svsIXoUOWlJ1/TCG4+DYfqi2fNi/A9BxQIJNw
PP2t4WFiw9k6GX6EsZkbAMUaC4J0niVQlGLH2ydxVyWN3amcOY6MIE9lX5Xa9/eH1sYITq726jTl
EBpbNU1341YheILcIRk13iSx0x1G/11fZU8xggL4MIIC9AIBATB2MGIxCzAJBgNVBAYTAlpBMSUw
IwYDVQQKExxUaGF3dGUgQ29uc3VsdGluZyAoUHR5KSBMdGQuMSwwKgYDVQQDEyNUaGF3dGUgUGVy
c29uYWwgRnJlZW1haWwgSXNzdWluZyBDQQIQSBvfXnHHcdTCDNkxvUvKXTAJBgUrDgMCGgUAoIIB
2DAYBgkqhkiG9w0BCQMxCwYJKoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xMDAyMTgyMDU2MDFa
MCMGCSqGSIb3DQEJBDEWBBRJqFlS/9lbZcatUDbHCHewW9wbmDBnBgkqhkiG9w0BCQ8xWjBYMAoG
CCqGSIb3DQMHMA4GCCqGSIb3DQMCAgIAgDANBggqhkiG9w0DAgIBQDAHBgUrDgMCBzANBggqhkiG
9w0DAgIBKDAHBgUrDgMCGjAKBggqhkiG9w0CBTCBhQYJKwYBBAGCNxAEMXgwdjBiMQswCQYDVQQG
EwJaQTElMCMGA1UEChMcVGhhd3RlIENvbnN1bHRpbmcgKFB0eSkgTHRkLjEsMCoGA1UEAxMjVGhh
d3RlIFBlcnNvbmFsIEZyZWVtYWlsIElzc3VpbmcgQ0ECEEgb315xx3HUwgzZMb1Lyl0wgYcGCyqG
SIb3DQEJEAILMXigdjBiMQswCQYDVQQGEwJaQTElMCMGA1UEChMcVGhhd3RlIENvbnN1bHRpbmcg
KFB0eSkgTHRkLjEsMCoGA1UEAxMjVGhhd3RlIFBlcnNvbmFsIEZyZWVtYWlsIElzc3VpbmcgQ0EC
EEgb315xx3HUwgzZMb1Lyl0wDQYJKoZIhvcNAQEBBQAEgYCbA6RCcac/MThM5B4SY6QSvkLxbGpT
UwTOBc7h7tTa4Ur7PxazzlTUU/WMxl46TGMPA8tIxGbVr3QOh6A6Yqy2wRtPIDOxFvptueRPlKTU
l9n9ZH6v2SgeJHTt4ohJWgW9lEfriBNtofCIHADcFVrGaxwV4fRyKST6x1fU24kLiAAAAAAAAA==

------=_NextPart_000_0008_01CAB0AA.7C782D20--

--===============0426857873==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
lb-l mailing list
[email protected]
http://vegan.net/mailman/listinfo/lb-l
Searchable Archive: http://vegan.net/lb/archive
http://lbdigest.com Load Balancing Digest
http://lbwiki.com Load Balancing Wiki

--===============0426857873==--