Re: SSL w/ PCI best practices
Bill Blackford <[email protected]> Tue, 23 Feb 2010 19:41:08 -0800
| Newsgroups | gmane.comp.programming.load-balancing.general |
|---|---|
| Message-ID | <[email protected]> |
--===============2129398702== Content-Type: multipart/alternative; boundary=000e0cd70744d094470480506f1a --000e0cd70744d094470480506f1a Content-Type: text/plain; charset=windows-1252 Content-Transfer-Encoding: quoted-printable I also am not a PCI expert, but as I recall, we did the same (the secure zone concept) and were compliant. -b On Thu, Feb 18, 2010 at 11:42 AM, Kenneth Salchow <[email protected]> wrote: > If you re-encrypt, the benefit is in the reduced cost of the client side > sever certs as you can use internally generated ones between the > load-balancer and the physical servers; you also can often use certificat= es > with less strength and increase the SSL ID life to prevent frequent > key-exchange, which will also provide some benefit to the actual server. > Since the encryption is terminated, the load-balancer can allow you to sh= oot > the traffic to more advanced inspection and security services (like a WAF= ) > before re-encrypting it and sending it back to the server. For the same > reason, you can still apply many acceleration capabilities like > caching/compression/etc. on the Load-balancer, which can still provide > benefit to the overall transaction and a reduction of overhead on the > servers themselves. Lastly, the load balancer is still providing basic T= CP > optimization like request pipe-lining which can still improve backend ser= ver > performance. > > > > I=92d also like to point out that=97while I am certainly not speaking on = terms > of being a PCI expert=97I know that historically, as long as the path bet= ween > the load-balancer and the physical server is within a secure zone, many > organizations have not actually re-encrypted the traffic. This is entire= ly > based on the interpretation of the PCI standard, the architecture of your > environment and the amount of risk associated with doing it. Again, I ha= ve > not been directly active within the PCI compliance world for some time an= d > have never gone through an actual audit. Others on the list may have mor= e > input/experience with whether or not re-encryption is or isn=92t an optio= n. I > can only speak from past experience. > > > > But, if it is a mandate for your environment, hopefully I helped point ou= t > some reasons why an ADC can still provide some significant benefit. > > > > Good luck! > > > > *KJ (Ken) Salchow, Jr.* | Manager, Technical Marketing > > *D 651.423.1133* > > *M 612.868.1258* > > *P 206.272.5555* > > *F 206.272.5555* > > *www.f5.com* > > > > > > *From:* [email protected] [mailto:[email protected]] *On Behalf > Of *Van Ceylon, David > *Sent:* Thursday, February 18, 2010 1:01 PM > *To:* 'Load Balancing Mailing List' > *Subject:* [load balancing] SSL w/ PCI best practices > > > > Hello =96 > > > > I have a question regarding the use of SSL while trying to maintain PCI > compliance. If a load balancer/SSL accelerator is handling SSL, what > advantage is that in terms of SSL offload if we must re-encrypt back to t= he > servers? This essentially limits the load balancer to URI inspection and > distributing traffic. There seems to be no advantage to handling Certs > (other than wildcard) or de-encryption. Forgive my ignorance but I=92m > looking for basic best practices in this situation. > > > > Thanks! > > > > David VanCeylon > > > > > ------------------------------ > > This communication is the property of Qwest and may contain confidential = or > privileged information. Unauthorized use of this communication is strictl= y > prohibited and may be unlawful. If you have received this communication > in error, please immediately notify the sender by reply e-mail and destro= y > all copies of the communication and any attachments. > > _______________________________________________ > lb-l mailing list > [email protected] > http://vegan.net/mailman/listinfo/lb-l > Searchable Archive: http://vegan.net/lb/archive > http://lbdigest.com Load Balancing Digest > http://lbwiki.com Load Balancing Wiki > > --=20 Bill Blackford Network Engineer Logged into reality and abusing my sudo privileges..... --000e0cd70744d094470480506f1a Content-Type: text/html; charset=windows-1252 Content-Transfer-Encoding: quoted-printable I also am not a PCI expert, but as I recall, we did the same (the secure zo= ne concept) and were=A0compliant.=A0<div>-b<br><br><div class=3D"gmail_quot= e">On Thu, Feb 18, 2010 at 11:42 AM, Kenneth Salchow <span dir=3D"ltr"><= <a href=3D"mailto:[email protected]">[email protected]</a>></span> wrote:<= br> <blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p= x #ccc solid;padding-left:1ex;"> <div lang=3D"EN-US" link=3D"blue" vlink=3D"#606420"> <div> <p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;color:#1F497D">If yo= u re-encrypt, the benefit is in the reduced cost of the client side sever certs as you can use internally generated ones between the load-balancer and the physical servers; you also can often use certificates with less strength and increase the SSL ID life to prevent frequent key-exchange, which will also provide some benefit to the actual server.=A0= Since the encryption is terminated, the load-balancer can allow you to shoot the traffic to more advanced inspection and security services (like a WAF) befo= re re-encrypting it and sending it back to the server.=A0 For the same reason, you can still apply many acceleration capabilities like caching/compression/etc. on the Load-balancer, which can still provide bene= fit to the overall transaction and a reduction of overhead on the servers themselves.=A0 Lastly, the load balancer is still providing basic TCP optimization like request pipe-lining which can still improve backend serve= r performance.</span></p> <p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;color:#1F497D">=A0</= span></p> <p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;color:#1F497D">I=92d= also like to point out that=97while I am certainly not speaking on terms of being a PCI expert=97I know that historically, as long as the path between the load-balancer and the physical server is withi= n a secure zone, many organizations have not actually re-encrypted the traffic.=A0 This is entirely based on the interpretation of the PCI standar= d, the architecture of your environment and the amount of risk associated with doing it.=A0 Again, I have not been directly active within the PCI compliance world for some time and have never gone through an actual audit.=A0 Others on the list may have more input/experience with whether or not re-encryption is or isn=92t an option.=A0 I can only speak from past experience.</span></p> <p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;color:#1F497D">=A0</= span></p> <p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;color:#1F497D">But, = if it is a mandate for your environment, hopefully I helped point out some reasons why an ADC can still provide some significant benefi= t.</span></p> <p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;color:#1F497D">=A0</= span></p> <p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;color:#1F497D">Good = luck!</span></p> <p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;color:#1F497D">=A0</= span></p> <div> <table border=3D"0" cellpadding=3D"0" width=3D"425" style=3D"width:318.75pt= "> <tbody><tr> <td colspan=3D"5" style=3D"padding:.75pt .75pt .75pt .75pt"> <p class=3D"MsoNormal"><b><span style=3D"font-size:10.0pt;color:#1F497D">= KJ (Ken) Salchow, Jr.</span></b><span style=3D"font-size:10.0pt;color:#1F49= 7D"> | Manager, Technical Marketing</span><span style=3D"color:#1F497D"></span></p> </td> </tr> <tr style=3D"min-height:9.0pt"> <td width=3D"84" style=3D"width:63.0pt;padding:.75pt .75pt .75pt .75pt;mi= n-height:9.0pt"> <p class=3D"MsoNormal" style=3D"line-height:9.0pt"><b><span style=3D"font= -size:7.5pt;color:#333333">D 651.423.1133</span></b><span style=3D"color:#1= F497D"></span></p> </td> <td width=3D"84" style=3D"width:63.0pt;padding:.75pt .75pt .75pt .75pt;mi= n-height:9.0pt"> <p class=3D"MsoNormal" style=3D"line-height:9.0pt"><b><span style=3D"font= -size:7.5pt;color:#333333">M 612.868.1258</span></b><span style=3D"color:#1= F497D"></span></p> </td> <td width=3D"84" style=3D"width:63.0pt;padding:.75pt .75pt .75pt .75pt;mi= n-height:9.0pt"> <p class=3D"MsoNormal" style=3D"line-height:9.0pt"><b><span style=3D"font= -size:7.5pt;color:#333333">P 206.272.5555</span></b><span style=3D"color:#1= F497D"></span></p> </td> <td width=3D"84" style=3D"width:63.0pt;padding:.75pt .75pt .75pt .75pt;mi= n-height:9.0pt"> <p class=3D"MsoNormal" style=3D"line-height:9.0pt"><b><span style=3D"font= -size:7.5pt;color:#333333">F 206.272.5555</span></b><span style=3D"color:#1= F497D"></span></p> </td> <td width=3D"69" style=3D"width:51.75pt;padding:.75pt .75pt .75pt .75pt;m= in-height:9.0pt"> <p class=3D"MsoNormal" style=3D"line-height:9.0pt"><b><span style=3D"font= -size:7.5pt;color:#333333"><a href=3D"http://www.f5.com/" target=3D"_blank"= ><span style=3D"color:#333333">www.f5.com</span></a></span></b><span style= =3D"color:#1F497D"></span></p> </td> </tr> </tbody></table> <p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;color:#1F497D">=A0</= span></p> <p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;color:#1F497D">=A0</= span></p> <div> <div style=3D"border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in = 0in 0in"> <p class=3D"MsoNormal" style=3D"margin-left:.5in"><b><span style=3D"font-si= ze:10.0pt">From:</span></b><span style=3D"font-size:10.0pt"> <a href=3D"mai= lto:[email protected]" target=3D"_blank">[email protected]</a> [mailto:<a href=3D"mailto:[email protected]" target=3D"_blank">lb-l-bo= [email protected]</a>] <b>On Behalf Of </b>Van Ceylon, David<br> <b>Sent:</b> Thursday, February 18, 2010 1:01 PM<br> <b>To:</b> 'Load Balancing Mailing List'<br> <b>Subject:</b> [load balancing] SSL w/ PCI best practices</span></p> </div> </div><div><div></div><div class=3D"h5"> <p class=3D"MsoNormal" style=3D"margin-left:.5in">=A0</p> <p class=3D"MsoNormal" style=3D"margin-left:.5in"><span style=3D"font-size:= 10.0pt">Hello =96 </span></p> <p class=3D"MsoNormal" style=3D"margin-left:.5in"><span style=3D"font-size:= 10.0pt">=A0</span></p> <p class=3D"MsoNormal" style=3D"margin-left:.5in"><span style=3D"font-size:= 10.0pt">I have a question regarding the use of SSL while trying to maintain PCI compliance. =A0If a load balancer/SSL accelerator is handling SSL, what advantage is that in terms of SSL offload= if we must re-encrypt back to the servers?=A0 This essentially limits the load balancer to URI inspection and distributing traffic.=A0 There seems to be n= o advantage to handling Certs (other than wildcard) or de-encryption. =A0Forgive my ignorance but I=92m looking for basic best practices in this situation.</span></p> <p class=3D"MsoNormal" style=3D"margin-left:.5in"><span style=3D"font-size:= 10.0pt">=A0</span></p> <p class=3D"MsoNormal" style=3D"margin-left:.5in"><span style=3D"font-size:= 10.0pt">Thanks!</span></p> <p class=3D"MsoNormal" style=3D"margin-left:.5in"><span style=3D"font-size:= 10.0pt">=A0</span></p> <p class=3D"MsoNormal" style=3D"margin-left:.5in"><span style=3D"font-size:= 10.0pt">David VanCeylon</span></p> <p class=3D"MsoNormal" style=3D"margin-left:.5in">=A0</p> <p class=3D"MsoNormal" style=3D"margin-left:.5in">=A0</p> <div class=3D"MsoNormal" align=3D"center" style=3D"margin-left:.5in;text-al= ign:center"> <hr size=3D"2" width=3D"100%" align=3D"center"> </div> <p class=3D"MsoNormal" style=3D"margin-left:.5in"><span style=3D"font-size:= 7.5pt;color:gray">This communication is the property of Qwest and may contain confidential or<br> privileged information. Unauthorized use of this communication is strictly<= br> prohibited and may be unlawful. If you have received this communication<br> in error, please immediately notify the sender by reply e-mail and destroy<= br> all copies of the communication and any attachments.</span></p> </div></div></div> </div> </div> <br>_______________________________________________<br> lb-l mailing list<br> <a href=3D"mailto:[email protected]">[email protected]</a><br> <a href=3D"http://vegan.net/mailman/listinfo/lb-l" target=3D"_blank">http:/= /vegan.net/mailman/listinfo/lb-l</a><br> Searchable Archive: <a href=3D"http://vegan.net/lb/archive" target=3D"_blan= k">http://vegan.net/lb/archive</a><br> <a href=3D"http://lbdigest.com" target=3D"_blank">http://lbdigest.com</a> L= oad Balancing Digest<br> <a href=3D"http://lbwiki.com" target=3D"_blank">http://lbwiki.com</a> Load = Balancing Wiki<br> <br></blockquote></div><br><br clear=3D"all"><br>-- <br>Bill Blackford<br>N= etwork Engineer <br><br>Logged into reality and abusing my sudo privileges.= ....<br> </div> --000e0cd70744d094470480506f1a-- --===============2129398702== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ lb-l mailing list [email protected] http://vegan.net/mailman/listinfo/lb-l Searchable Archive: http://vegan.net/lb/archive http://lbdigest.com Load Balancing Digest http://lbwiki.com Load Balancing Wiki --===============2129398702==--