SSL w/ PCI best practices

"Van Ceylon, David" <[email protected]> Thu, 18 Feb 2010 13:00:56 -0600
Newsgroups gmane.comp.programming.load-balancing.general
Message-ID <26D139D7C4E9784494738860A529B91E2825D13970@qtomaexmbm21.AD.QINTRA.COM>
--===============0426216629==
Content-Language: en-US
Content-Type: multipart/alternative;
	boundary="_000_26D139D7C4E9784494738860A529B91E2825D13970qtomaexmbm21A_"

--_000_26D139D7C4E9784494738860A529B91E2825D13970qtomaexmbm21A_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Hello -

I have a question regarding the use of SSL while trying to maintain PCI com=
pliance.  If a load balancer/SSL accelerator is handling SSL, what advantag=
e is that in terms of SSL offload if we must re-encrypt back to the servers=
?  This essentially limits the load balancer to URI inspection and distribu=
ting traffic.  There seems to be no advantage to handling Certs (other than=
 wildcard) or de-encryption.  Forgive my ignorance but I'm looking for basi=
c best practices in this situation.

Thanks!

David VanCeylon


________________________________
This communication is the property of Qwest and may contain confidential or
privileged information. Unauthorized use of this communication is strictly
prohibited and may be unlawful. If you have received this communication
in error, please immediately notify the sender by reply e-mail and destroy
all copies of the communication and any attachments.

--_000_26D139D7C4E9784494738860A529B91E2825D13970qtomaexmbm21A_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:o=3D"urn:schemas-microsoft-com:office:office" xmlns:w=3D"urn:sc=
hemas-microsoft-com:office:word" xmlns=3D"http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<meta name=3D"Generator" content=3D"Microsoft Word 11 (filtered medium)">
<style>
<!--
 /* Style Definitions */
 p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"Times New Roman";}
a:link, span.MsoHyperlink
	{color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{color:#606420;
	text-decoration:underline;}
span.EmailStyle17
	{mso-style-type:personal-compose;
	font-family:Arial;
	color:windowtext;}
@page Section1
	{size:8.5in 11.0in;
	margin:1.0in 1.25in 1.0in 1.25in;}
div.Section1
	{page:Section1;}
-->
</style>
</head>
<body lang=3D"EN-US" link=3D"blue" vlink=3D"#606420">
<div class=3D"Section1">
<p class=3D"MsoNormal"><font size=3D"2" face=3D"Arial"><span style=3D"font-=
size:10.0pt;
font-family:Arial">Hello &#8211;
<o:p></o:p></span></font></p>
<p class=3D"MsoNormal"><font size=3D"2" face=3D"Arial"><span style=3D"font-=
size:10.0pt;
font-family:Arial"><o:p>&nbsp;</o:p></span></font></p>
<p class=3D"MsoNormal"><font size=3D"2" face=3D"Arial"><span style=3D"font-=
size:10.0pt;
font-family:Arial">I have a question regarding the use of SSL while trying =
to maintain PCI compliance. &nbsp;If a load balancer/SSL accelerator is han=
dling SSL, what advantage is that
 in terms of SSL offload if we must re-encrypt back to the servers?&nbsp; T=
his essentially limits the load balancer to URI inspection and distributing=
 traffic.&nbsp; There seems to be no advantage to handling Certs (other tha=
n wildcard) or de-encryption. &nbsp;Forgive my
 ignorance but I&#8217;m looking for basic best practices in this situation=
.<o:p></o:p></span></font></p>
<p class=3D"MsoNormal"><font size=3D"2" face=3D"Arial"><span style=3D"font-=
size:10.0pt;
font-family:Arial"><o:p>&nbsp;</o:p></span></font></p>
<p class=3D"MsoNormal"><font size=3D"2" face=3D"Arial"><span style=3D"font-=
size:10.0pt;
font-family:Arial">Thanks!<o:p></o:p></span></font></p>
<p class=3D"MsoNormal"><font size=3D"2" face=3D"Arial"><span style=3D"font-=
size:10.0pt;
font-family:Arial"><o:p>&nbsp;</o:p></span></font></p>
<p class=3D"MsoNormal"><font size=3D"2" face=3D"Arial"><span style=3D"font-=
size:10.0pt;
font-family:Arial">David VanCeylon</span></font><o:p></o:p></p>
<p class=3D"MsoNormal"><font size=3D"3" face=3D"Times New Roman"><span styl=
e=3D"font-size:
12.0pt"><o:p>&nbsp;</o:p></span></font></p>
</div>
<br>
<hr>
<font face=3D"Arial" color=3D"Gray" size=3D"1">This communication is the pr=
operty of Qwest and may contain confidential or<br>
privileged information. Unauthorized use of this communication is strictly<=
br>
prohibited and may be unlawful. If you have received this communication<br>
in error, please immediately notify the sender by reply e-mail and destroy<=
br>
all copies of the communication and any attachments.<br>
</font>
</body>
</html>

--_000_26D139D7C4E9784494738860A529B91E2825D13970qtomaexmbm21A_--

--===============0426216629==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
lb-l mailing list
[email protected]
http://vegan.net/mailman/listinfo/lb-l
Searchable Archive: http://vegan.net/lb/archive
http://lbdigest.com Load Balancing Digest
http://lbwiki.com Load Balancing Wiki

--===============0426216629==--