Re: SSL w/ PCI best practices

Bill Blackford <[email protected]> Tue, 23 Feb 2010 19:41:08 -0800
Newsgroups gmane.comp.programming.load-balancing.general
Message-ID <[email protected]>
--===============2129398702==
Content-Type: multipart/alternative; boundary=000e0cd70744d094470480506f1a

--000e0cd70744d094470480506f1a
Content-Type: text/plain; charset=windows-1252
Content-Transfer-Encoding: quoted-printable

I also am not a PCI expert, but as I recall, we did the same (the secure
zone concept) and were compliant.
-b

On Thu, Feb 18, 2010 at 11:42 AM, Kenneth Salchow <[email protected]> wrote:

>  If you re-encrypt, the benefit is in the reduced cost of the client side
> sever certs as you can use internally generated ones between the
> load-balancer and the physical servers; you also can often use certificat=
es
> with less strength and increase the SSL ID life to prevent frequent
> key-exchange, which will also provide some benefit to the actual server.
> Since the encryption is terminated, the load-balancer can allow you to sh=
oot
> the traffic to more advanced inspection and security services (like a WAF=
)
> before re-encrypting it and sending it back to the server.  For the same
> reason, you can still apply many acceleration capabilities like
> caching/compression/etc. on the Load-balancer, which can still provide
> benefit to the overall transaction and a reduction of overhead on the
> servers themselves.  Lastly, the load balancer is still providing basic T=
CP
> optimization like request pipe-lining which can still improve backend ser=
ver
> performance.
>
>
>
> I=92d also like to point out that=97while I am certainly not speaking on =
terms
> of being a PCI expert=97I know that historically, as long as the path bet=
ween
> the load-balancer and the physical server is within a secure zone, many
> organizations have not actually re-encrypted the traffic.  This is entire=
ly
> based on the interpretation of the PCI standard, the architecture of your
> environment and the amount of risk associated with doing it.  Again, I ha=
ve
> not been directly active within the PCI compliance world for some time an=
d
> have never gone through an actual audit.  Others on the list may have mor=
e
> input/experience with whether or not re-encryption is or isn=92t an optio=
n.  I
> can only speak from past experience.
>
>
>
> But, if it is a mandate for your environment, hopefully I helped point ou=
t
> some reasons why an ADC can still provide some significant benefit.
>
>
>
> Good luck!
>
>
>
> *KJ (Ken) Salchow, Jr.* | Manager, Technical Marketing
>
> *D 651.423.1133*
>
> *M 612.868.1258*
>
> *P 206.272.5555*
>
> *F 206.272.5555*
>
> *www.f5.com*
>
>
>
>
>
> *From:* [email protected] [mailto:[email protected]] *On Behalf
> Of *Van Ceylon, David
> *Sent:* Thursday, February 18, 2010 1:01 PM
> *To:* 'Load Balancing Mailing List'
> *Subject:* [load balancing] SSL w/ PCI best practices
>
>
>
> Hello =96
>
>
>
> I have a question regarding the use of SSL while trying to maintain PCI
> compliance.  If a load balancer/SSL accelerator is handling SSL, what
> advantage is that in terms of SSL offload if we must re-encrypt back to t=
he
> servers?  This essentially limits the load balancer to URI inspection and
> distributing traffic.  There seems to be no advantage to handling Certs
> (other than wildcard) or de-encryption.  Forgive my ignorance but I=92m
> looking for basic best practices in this situation.
>
>
>
> Thanks!
>
>
>
> David VanCeylon
>
>
>
>
>  ------------------------------
>
> This communication is the property of Qwest and may contain confidential =
or
> privileged information. Unauthorized use of this communication is strictl=
y
> prohibited and may be unlawful. If you have received this communication
> in error, please immediately notify the sender by reply e-mail and destro=
y
> all copies of the communication and any attachments.
>
> _______________________________________________
> lb-l mailing list
> [email protected]
> http://vegan.net/mailman/listinfo/lb-l
> Searchable Archive: http://vegan.net/lb/archive
> http://lbdigest.com Load Balancing Digest
> http://lbwiki.com Load Balancing Wiki
>
>


--=20
Bill Blackford
Network Engineer

Logged into reality and abusing my sudo privileges.....

--000e0cd70744d094470480506f1a
Content-Type: text/html; charset=windows-1252
Content-Transfer-Encoding: quoted-printable

I also am not a PCI expert, but as I recall, we did the same (the secure zo=
ne concept) and were=A0compliant.=A0<div>-b<br><br><div class=3D"gmail_quot=
e">On Thu, Feb 18, 2010 at 11:42 AM, Kenneth Salchow <span dir=3D"ltr">&lt;=
<a href=3D"mailto:[email protected]">[email protected]</a>&gt;</span> wrote:<=
br>
<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex;">









<div lang=3D"EN-US" link=3D"blue" vlink=3D"#606420">

<div>

<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;color:#1F497D">If yo=
u re-encrypt, the benefit is in the reduced cost of the client
side sever certs as you can use internally generated ones between the
load-balancer and the physical servers; you also can often use certificates
with less strength and increase the SSL ID life to prevent frequent
key-exchange, which will also provide some benefit to the actual server.=A0=
 Since
the encryption is terminated, the load-balancer can allow you to shoot the
traffic to more advanced inspection and security services (like a WAF) befo=
re
re-encrypting it and sending it back to the server.=A0 For the same reason,
you can still apply many acceleration capabilities like
caching/compression/etc. on the Load-balancer, which can still provide bene=
fit
to the overall transaction and a reduction of overhead on the servers
themselves.=A0 Lastly, the load balancer is still providing basic TCP
optimization like request pipe-lining which can still improve backend serve=
r
performance.</span></p>

<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;color:#1F497D">=A0</=
span></p>

<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;color:#1F497D">I=92d=
 also like to point out that=97while I am certainly
not speaking on terms of being a PCI expert=97I know that historically, as
long as the path between the load-balancer and the physical server is withi=
n a
secure zone, many organizations have not actually re-encrypted the
traffic.=A0 This is entirely based on the interpretation of the PCI standar=
d,
the architecture of your environment and the amount of risk associated with
doing it.=A0 Again, I have not been directly active within the PCI
compliance world for some time and have never gone through an actual
audit.=A0 Others on the list may have more input/experience with whether or
not re-encryption is or isn=92t an option.=A0 I can only speak from past
experience.</span></p>

<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;color:#1F497D">=A0</=
span></p>

<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;color:#1F497D">But, =
if it is a mandate for your environment, hopefully I helped
point out some reasons why an ADC can still provide some significant benefi=
t.</span></p>

<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;color:#1F497D">=A0</=
span></p>

<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;color:#1F497D">Good =
luck!</span></p>

<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;color:#1F497D">=A0</=
span></p>

<div>

<table border=3D"0" cellpadding=3D"0" width=3D"425" style=3D"width:318.75pt=
">
 <tbody><tr>
  <td colspan=3D"5" style=3D"padding:.75pt .75pt .75pt .75pt">
  <p class=3D"MsoNormal"><b><span style=3D"font-size:10.0pt;color:#1F497D">=
KJ (Ken) Salchow, Jr.</span></b><span style=3D"font-size:10.0pt;color:#1F49=
7D"> | Manager, Technical
  Marketing</span><span style=3D"color:#1F497D"></span></p>
  </td>
 </tr>
 <tr style=3D"min-height:9.0pt">
  <td width=3D"84" style=3D"width:63.0pt;padding:.75pt .75pt .75pt .75pt;mi=
n-height:9.0pt">
  <p class=3D"MsoNormal" style=3D"line-height:9.0pt"><b><span style=3D"font=
-size:7.5pt;color:#333333">D 651.423.1133</span></b><span style=3D"color:#1=
F497D"></span></p>
  </td>
  <td width=3D"84" style=3D"width:63.0pt;padding:.75pt .75pt .75pt .75pt;mi=
n-height:9.0pt">
  <p class=3D"MsoNormal" style=3D"line-height:9.0pt"><b><span style=3D"font=
-size:7.5pt;color:#333333">M 612.868.1258</span></b><span style=3D"color:#1=
F497D"></span></p>
  </td>
  <td width=3D"84" style=3D"width:63.0pt;padding:.75pt .75pt .75pt .75pt;mi=
n-height:9.0pt">
  <p class=3D"MsoNormal" style=3D"line-height:9.0pt"><b><span style=3D"font=
-size:7.5pt;color:#333333">P 206.272.5555</span></b><span style=3D"color:#1=
F497D"></span></p>
  </td>
  <td width=3D"84" style=3D"width:63.0pt;padding:.75pt .75pt .75pt .75pt;mi=
n-height:9.0pt">
  <p class=3D"MsoNormal" style=3D"line-height:9.0pt"><b><span style=3D"font=
-size:7.5pt;color:#333333">F 206.272.5555</span></b><span style=3D"color:#1=
F497D"></span></p>
  </td>
  <td width=3D"69" style=3D"width:51.75pt;padding:.75pt .75pt .75pt .75pt;m=
in-height:9.0pt">
  <p class=3D"MsoNormal" style=3D"line-height:9.0pt"><b><span style=3D"font=
-size:7.5pt;color:#333333"><a href=3D"http://www.f5.com/" target=3D"_blank"=
><span style=3D"color:#333333">www.f5.com</span></a></span></b><span style=
=3D"color:#1F497D"></span></p>

  </td>
 </tr>
</tbody></table>

<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;color:#1F497D">=A0</=
span></p>

<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;color:#1F497D">=A0</=
span></p>

<div>

<div style=3D"border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in =
0in 0in">

<p class=3D"MsoNormal" style=3D"margin-left:.5in"><b><span style=3D"font-si=
ze:10.0pt">From:</span></b><span style=3D"font-size:10.0pt"> <a href=3D"mai=
lto:[email protected]" target=3D"_blank">[email protected]</a>
[mailto:<a href=3D"mailto:[email protected]" target=3D"_blank">lb-l-bo=
[email protected]</a>] <b>On Behalf Of </b>Van Ceylon, David<br>
<b>Sent:</b> Thursday, February 18, 2010 1:01 PM<br>
<b>To:</b> &#39;Load Balancing Mailing List&#39;<br>
<b>Subject:</b> [load balancing] SSL w/ PCI best practices</span></p>

</div>

</div><div><div></div><div class=3D"h5">

<p class=3D"MsoNormal" style=3D"margin-left:.5in">=A0</p>

<p class=3D"MsoNormal" style=3D"margin-left:.5in"><span style=3D"font-size:=
10.0pt">Hello =96 </span></p>

<p class=3D"MsoNormal" style=3D"margin-left:.5in"><span style=3D"font-size:=
10.0pt">=A0</span></p>

<p class=3D"MsoNormal" style=3D"margin-left:.5in"><span style=3D"font-size:=
10.0pt">I have a question regarding the use of SSL
while trying to maintain PCI compliance. =A0If a load balancer/SSL
accelerator is handling SSL, what advantage is that in terms of SSL offload=
 if
we must re-encrypt back to the servers?=A0 This essentially limits the load
balancer to URI inspection and distributing traffic.=A0 There seems to be n=
o
advantage to handling Certs (other than wildcard) or de-encryption.
=A0Forgive my ignorance but I=92m looking for basic best practices in
this situation.</span></p>

<p class=3D"MsoNormal" style=3D"margin-left:.5in"><span style=3D"font-size:=
10.0pt">=A0</span></p>

<p class=3D"MsoNormal" style=3D"margin-left:.5in"><span style=3D"font-size:=
10.0pt">Thanks!</span></p>

<p class=3D"MsoNormal" style=3D"margin-left:.5in"><span style=3D"font-size:=
10.0pt">=A0</span></p>

<p class=3D"MsoNormal" style=3D"margin-left:.5in"><span style=3D"font-size:=
10.0pt">David VanCeylon</span></p>

<p class=3D"MsoNormal" style=3D"margin-left:.5in">=A0</p>

<p class=3D"MsoNormal" style=3D"margin-left:.5in">=A0</p>

<div class=3D"MsoNormal" align=3D"center" style=3D"margin-left:.5in;text-al=
ign:center">

<hr size=3D"2" width=3D"100%" align=3D"center">

</div>

<p class=3D"MsoNormal" style=3D"margin-left:.5in"><span style=3D"font-size:=
7.5pt;color:gray">This communication is the property
of Qwest and may contain confidential or<br>
privileged information. Unauthorized use of this communication is strictly<=
br>
prohibited and may be unlawful. If you have received this communication<br>
in error, please immediately notify the sender by reply e-mail and destroy<=
br>
all copies of the communication and any attachments.</span></p>

</div></div></div>

</div>

</div>


<br>_______________________________________________<br>
lb-l mailing list<br>
<a href=3D"mailto:[email protected]">[email protected]</a><br>
<a href=3D"http://vegan.net/mailman/listinfo/lb-l" target=3D"_blank">http:/=
/vegan.net/mailman/listinfo/lb-l</a><br>
Searchable Archive: <a href=3D"http://vegan.net/lb/archive" target=3D"_blan=
k">http://vegan.net/lb/archive</a><br>
<a href=3D"http://lbdigest.com" target=3D"_blank">http://lbdigest.com</a> L=
oad Balancing Digest<br>
<a href=3D"http://lbwiki.com" target=3D"_blank">http://lbwiki.com</a> Load =
Balancing Wiki<br>
<br></blockquote></div><br><br clear=3D"all"><br>-- <br>Bill Blackford<br>N=
etwork Engineer <br><br>Logged into reality and abusing my sudo privileges.=
....<br>
</div>

--000e0cd70744d094470480506f1a--

--===============2129398702==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
lb-l mailing list
[email protected]
http://vegan.net/mailman/listinfo/lb-l
Searchable Archive: http://vegan.net/lb/archive
http://lbdigest.com Load Balancing Digest
http://lbwiki.com Load Balancing Wiki

--===============2129398702==--