Re: SSL w/ PCI best practices

Kenneth Salchow <[email protected]> Wed, 24 Feb 2010 08:54:04 -0800
Newsgroups gmane.comp.programming.load-balancing.general
Message-ID <4B18A8F75A6384449755BC7784073E93616E8F4B8E@exch11.olympus.f5net.com>
--===============1201749382==
Content-Language: en-US
Content-Type: multipart/signed; protocol="application/x-pkcs7-signature";
	micalg=SHA1; boundary="----=_NextPart_000_0799_01CAB53F.AE685280"

------=_NextPart_000_0799_01CAB53F.AE685280
Content-Type: multipart/alternative;
	boundary="----=_NextPart_001_079A_01CAB53F.AE685280"


------=_NextPart_001_079A_01CAB53F.AE685280
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: 7bit

Bill-

 

Thanks for the verification.  I know this was a HUGE security debate back in
2000 when we started doing the ssl termination, but I think over the years
people have come to agree on the fact that as long s the traffic stays
within a secure zone, with limited electronic and physical access, that it
is ok.

 


KJ (Ken) Salchow, Jr. | Manager, Technical Marketing


D 651.423.1133

M 612.868.1258

P 206.272.5555

F 206.272.5555

 <http://www.f5.com/> www.f5.com

 

 

From: [email protected] [mailto:[email protected]] On Behalf Of
Bill Blackford
Sent: Tuesday, February 23, 2010 9:41 PM
To: Load Balancing Mailing List
Subject: Re: [load balancing] SSL w/ PCI best practices

 

I also am not a PCI expert, but as I recall, we did the same (the secure
zone concept) and were compliant. 

-b

On Thu, Feb 18, 2010 at 11:42 AM, Kenneth Salchow <[email protected]> wrote:

If you re-encrypt, the benefit is in the reduced cost of the client side
sever certs as you can use internally generated ones between the
load-balancer and the physical servers; you also can often use certificates
with less strength and increase the SSL ID life to prevent frequent
key-exchange, which will also provide some benefit to the actual server.
Since the encryption is terminated, the load-balancer can allow you to shoot
the traffic to more advanced inspection and security services (like a WAF)
before re-encrypting it and sending it back to the server.  For the same
reason, you can still apply many acceleration capabilities like
caching/compression/etc. on the Load-balancer, which can still provide
benefit to the overall transaction and a reduction of overhead on the
servers themselves.  Lastly, the load balancer is still providing basic TCP
optimization like request pipe-lining which can still improve backend server
performance.

 

I'd also like to point out that-while I am certainly not speaking on terms
of being a PCI expert-I know that historically, as long as the path between
the load-balancer and the physical server is within a secure zone, many
organizations have not actually re-encrypted the traffic.  This is entirely
based on the interpretation of the PCI standard, the architecture of your
environment and the amount of risk associated with doing it.  Again, I have
not been directly active within the PCI compliance world for some time and
have never gone through an actual audit.  Others on the list may have more
input/experience with whether or not re-encryption is or isn't an option.  I
can only speak from past experience.

 

But, if it is a mandate for your environment, hopefully I helped point out
some reasons why an ADC can still provide some significant benefit.

 

Good luck!

 


KJ (Ken) Salchow, Jr. | Manager, Technical Marketing


D 651.423.1133

M 612.868.1258

P 206.272.5555

F 206.272.5555

 <http://www.f5.com/> www.f5.com

 

 

From: [email protected] [mailto:[email protected]] On Behalf Of
Van Ceylon, David
Sent: Thursday, February 18, 2010 1:01 PM
To: 'Load Balancing Mailing List'
Subject: [load balancing] SSL w/ PCI best practices

 

Hello - 

 

I have a question regarding the use of SSL while trying to maintain PCI
compliance.  If a load balancer/SSL accelerator is handling SSL, what
advantage is that in terms of SSL offload if we must re-encrypt back to the
servers?  This essentially limits the load balancer to URI inspection and
distributing traffic.  There seems to be no advantage to handling Certs
(other than wildcard) or de-encryption.  Forgive my ignorance but I'm
looking for basic best practices in this situation.

 

Thanks!

 

David VanCeylon

 

 

  _____  

This communication is the property of Qwest and may contain confidential or
privileged information. Unauthorized use of this communication is strictly
prohibited and may be unlawful. If you have received this communication
in error, please immediately notify the sender by reply e-mail and destroy
all copies of the communication and any attachments.


_______________________________________________
lb-l mailing list
[email protected]
http://vegan.net/mailman/listinfo/lb-l
Searchable Archive: http://vegan.net/lb/archive
http://lbdigest.com Load Balancing Digest
http://lbwiki.com Load Balancing Wiki




-- 
Bill Blackford
Network Engineer 

Logged into reality and abusing my sudo privileges.....


------=_NextPart_001_079A_01CAB53F.AE685280
Content-Type: text/html;
	charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" =
xmlns:o=3D"urn:schemas-microsoft-com:office:office" =
xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:x=3D"urn:schemas-microsoft-com:office:excel" =
xmlns:p=3D"urn:schemas-microsoft-com:office:powerpoint" =
xmlns:a=3D"urn:schemas-microsoft-com:office:access" =
xmlns:dt=3D"uuid:C2F41010-65B3-11d1-A29F-00AA00C14882" =
xmlns:s=3D"uuid:BDC6E3F0-6DA3-11d1-A2A3-00AA00C14882" =
xmlns:rs=3D"urn:schemas-microsoft-com:rowset" xmlns:z=3D"#RowsetSchema" =
xmlns:b=3D"urn:schemas-microsoft-com:office:publisher" =
xmlns:ss=3D"urn:schemas-microsoft-com:office:spreadsheet" =
xmlns:c=3D"urn:schemas-microsoft-com:office:component:spreadsheet" =
xmlns:odc=3D"urn:schemas-microsoft-com:office:odc" =
xmlns:oa=3D"urn:schemas-microsoft-com:office:activation" =
xmlns:html=3D"http://www.w3.org/TR/REC-html40" =
xmlns:q=3D"http://schemas.xmlsoap.org/soap/envelope/" =
xmlns:rtc=3D"http://microsoft.com/officenet/conferencing" =
xmlns:D=3D"DAV:" xmlns:Repl=3D"http://schemas.microsoft.com/repl/" =
xmlns:mt=3D"http://schemas.microsoft.com/sharepoint/soap/meetings/" =
xmlns:x2=3D"http://schemas.microsoft.com/office/excel/2003/xml" =
xmlns:ppda=3D"http://www.passport.com/NameSpace.xsd" =
xmlns:ois=3D"http://schemas.microsoft.com/sharepoint/soap/ois/" =
xmlns:dir=3D"http://schemas.microsoft.com/sharepoint/soap/directory/" =
xmlns:ds=3D"http://www.w3.org/2000/09/xmldsig#" =
xmlns:dsp=3D"http://schemas.microsoft.com/sharepoint/dsp" =
xmlns:udc=3D"http://schemas.microsoft.com/data/udc" =
xmlns:xsd=3D"http://www.w3.org/2001/XMLSchema" =
xmlns:sub=3D"http://schemas.microsoft.com/sharepoint/soap/2002/1/alerts/"=
 xmlns:ec=3D"http://www.w3.org/2001/04/xmlenc#" =
xmlns:sp=3D"http://schemas.microsoft.com/sharepoint/" =
xmlns:sps=3D"http://schemas.microsoft.com/sharepoint/soap/" =
xmlns:xsi=3D"http://www.w3.org/2001/XMLSchema-instance" =
xmlns:udcs=3D"http://schemas.microsoft.com/data/udc/soap" =
xmlns:udcxf=3D"http://schemas.microsoft.com/data/udc/xmlfile" =
xmlns:udcp2p=3D"http://schemas.microsoft.com/data/udc/parttopart" =
xmlns:wf=3D"http://schemas.microsoft.com/sharepoint/soap/workflow/" =
xmlns:dsss=3D"http://schemas.microsoft.com/office/2006/digsig-setup" =
xmlns:dssi=3D"http://schemas.microsoft.com/office/2006/digsig" =
xmlns:mdssi=3D"http://schemas.openxmlformats.org/package/2006/digital-sig=
nature" =
xmlns:mver=3D"http://schemas.openxmlformats.org/markup-compatibility/2006=
" xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" =
xmlns:mrels=3D"http://schemas.openxmlformats.org/package/2006/relationshi=
ps" xmlns:spwp=3D"http://microsoft.com/sharepoint/webpartpages" =
xmlns:ex12t=3D"http://schemas.microsoft.com/exchange/services/2006/types"=
 =
xmlns:ex12m=3D"http://schemas.microsoft.com/exchange/services/2006/messag=
es" =
xmlns:pptsl=3D"http://schemas.microsoft.com/sharepoint/soap/SlideLibrary/=
" =
xmlns:spsl=3D"http://microsoft.com/webservices/SharePointPortalServer/Pub=
lishedLinksService" xmlns:Z=3D"urn:schemas-microsoft-com:" =
xmlns:st=3D"&#1;" xmlns=3D"http://www.w3.org/TR/REC-html40">

<head>
<meta http-equiv=3DContent-Type content=3D"text/html; =
charset=3Dus-ascii">
<meta name=3DGenerator content=3D"Microsoft Word 12 (filtered medium)">
<!--[if !mso]>
<style>
v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style>
<![endif]-->
<style>
<!--
 /* Font Definitions */
 @font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
 /* Style Definitions */
 p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
span.EmailStyle17
	{mso-style-type:personal-reply;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
.MsoChpDefault
	{mso-style-type:export-only;}
@page Section1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.Section1
	{page:Section1;}
-->
</style>
<!--[if gte mso 9]><xml>
 <o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
 <o:shapelayout v:ext=3D"edit">
  <o:idmap v:ext=3D"edit" data=3D"1" />
 </o:shapelayout></xml><![endif]-->
</head>

<body lang=3DEN-US link=3Dblue vlink=3Dpurple>

<div class=3DSection1>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>Bill&#8212;<o:p></o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p>&nbsp;</o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'>Thanks for the verification.&nbsp; I know this was a HUGE
security debate back in 2000 when we started doing the ssl termination, =
but I
think over the years people have come to agree on the fact that as long =
s the
traffic stays within a secure zone, with limited electronic and physical
access, that it is ok.<o:p></o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p>&nbsp;</o:p></span></p>

<table class=3DMsoNormalTable border=3D0 cellpadding=3D0 width=3D425 =
style=3D'width:318.75pt'>
 <tr>
  <td colspan=3D5 style=3D'padding:.75pt .75pt .75pt .75pt'>
  <p class=3DMsoNormal><b><span =
style=3D'font-size:10.0pt;font-family:"Arial","sans-serif";
  color:#1F497D'>KJ (Ken) Salchow, Jr.</span></b><span =
style=3D'font-size:10.0pt;
  font-family:"Arial","sans-serif";color:#1F497D'> | Manager, Technical
  Marketing</span><span =
style=3D'font-family:"Calibri","sans-serif";color:#1F497D'><o:p></o:p></s=
pan></p>
  </td>
 </tr>
 <tr style=3D'height:9.0pt'>
  <td width=3D84 style=3D'width:63.0pt;padding:.75pt .75pt .75pt =
.75pt;height:9.0pt'>
  <p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;
  line-height:9.0pt'><b><span =
style=3D'font-size:7.5pt;font-family:"Arial","sans-serif";
  color:#333333'>D 651.423.1133</span></b><span =
style=3D'color:#1F497D'><o:p></o:p></span></p>
  </td>
  <td width=3D84 style=3D'width:63.0pt;padding:.75pt .75pt .75pt =
.75pt;height:9.0pt'>
  <p class=3DMsoNormal style=3D'line-height:9.0pt'><b><span =
style=3D'font-size:7.5pt;
  font-family:"Arial","sans-serif";color:#333333'>M =
612.868.1258</span></b><span
  =
style=3D'font-family:"Calibri","sans-serif";color:#1F497D'><o:p></o:p></s=
pan></p>
  </td>
  <td width=3D84 style=3D'width:63.0pt;padding:.75pt .75pt .75pt =
.75pt;height:9.0pt'>
  <p class=3DMsoNormal style=3D'line-height:9.0pt'><b><span =
style=3D'font-size:7.5pt;
  font-family:"Arial","sans-serif";color:#333333'>P =
206.272.5555</span></b><span
  =
style=3D'font-family:"Calibri","sans-serif";color:#1F497D'><o:p></o:p></s=
pan></p>
  </td>
  <td width=3D84 style=3D'width:63.0pt;padding:.75pt .75pt .75pt =
.75pt;height:9.0pt'>
  <p class=3DMsoNormal style=3D'line-height:9.0pt'><b><span =
style=3D'font-size:7.5pt;
  font-family:"Arial","sans-serif";color:#333333'>F =
206.272.5555</span></b><span
  =
style=3D'font-family:"Calibri","sans-serif";color:#1F497D'><o:p></o:p></s=
pan></p>
  </td>
  <td width=3D69 style=3D'width:51.75pt;padding:.75pt .75pt .75pt =
.75pt;height:
  9.0pt'>
  <p class=3DMsoNormal style=3D'line-height:9.0pt'><b><span =
style=3D'font-size:7.5pt;
  font-family:"Arial","sans-serif";color:#333333'><a =
href=3D"http://www.f5.com/"><span
  style=3D'color:#333333'>www.f5.com</span></a></span></b><span =
style=3D'font-family:
  "Calibri","sans-serif";color:#1F497D'><o:p></o:p></span></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p>&nbsp;</o:p></span></p>

<p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";
color:#1F497D'><o:p>&nbsp;</o:p></span></p>

<div style=3D'border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt =
0in 0in 0in'>

<p class=3DMsoNormal style=3D'margin-left:.5in'><b><span =
style=3D'font-size:10.0pt;
font-family:"Tahoma","sans-serif"'>From:</span></b><span =
style=3D'font-size:10.0pt;
font-family:"Tahoma","sans-serif"'> [email protected]
[mailto:[email protected]] <b>On Behalf Of </b>Bill Blackford<br>
<b>Sent:</b> Tuesday, February 23, 2010 9:41 PM<br>
<b>To:</b> Load Balancing Mailing List<br>
<b>Subject:</b> Re: [load balancing] SSL w/ PCI best =
practices<o:p></o:p></span></p>

</div>

<p class=3DMsoNormal style=3D'margin-left:.5in'><o:p>&nbsp;</o:p></p>

<p class=3DMsoNormal style=3D'margin-left:.5in'>I also am not a PCI =
expert, but as
I recall, we did the same (the secure zone concept) and
were&nbsp;compliant.&nbsp;<o:p></o:p></p>

<div>

<p class=3DMsoNormal =
style=3D'mso-margin-top-alt:0in;margin-right:0in;margin-bottom:
12.0pt;margin-left:.5in'>-b<o:p></o:p></p>

<div>

<p class=3DMsoNormal style=3D'margin-left:.5in'>On Thu, Feb 18, 2010 at =
11:42 AM,
Kenneth Salchow &lt;<a =
href=3D"mailto:[email protected]">[email protected]</a>&gt;
wrote:<o:p></o:p></p>

<div>

<div>

<p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;
margin-left:.5in'><span style=3D'font-size:11.0pt;color:#1F497D'>If you
re-encrypt, the benefit is in the reduced cost of the client side sever =
certs
as you can use internally generated ones between the load-balancer and =
the
physical servers; you also can often use certificates with less strength =
and
increase the SSL ID life to prevent frequent key-exchange, which will =
also
provide some benefit to the actual server.&nbsp; Since the encryption is
terminated, the load-balancer can allow you to shoot the traffic to more
advanced inspection and security services (like a WAF) before =
re-encrypting it
and sending it back to the server.&nbsp; For the same reason, you can =
still
apply many acceleration capabilities like caching/compression/etc. on =
the
Load-balancer, which can still provide benefit to the overall =
transaction and a
reduction of overhead on the servers themselves.&nbsp; Lastly, the load
balancer is still providing basic TCP optimization like request =
pipe-lining
which can still improve backend server =
performance.</span><o:p></o:p></p>

<p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;
margin-left:.5in'><span =
style=3D'font-size:11.0pt;color:#1F497D'>&nbsp;</span><o:p></o:p></p>

<p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;
margin-left:.5in'><span =
style=3D'font-size:11.0pt;color:#1F497D'>I&#8217;d also
like to point out that&#8212;while I am certainly not speaking on terms =
of
being a PCI expert&#8212;I know that historically, as long as the path =
between
the load-balancer and the physical server is within a secure zone, many
organizations have not actually re-encrypted the traffic.&nbsp; This is
entirely based on the interpretation of the PCI standard, the =
architecture of
your environment and the amount of risk associated with doing it.&nbsp; =
Again,
I have not been directly active within the PCI compliance world for some =
time
and have never gone through an actual audit.&nbsp; Others on the list =
may have
more input/experience with whether or not re-encryption is or =
isn&#8217;t an
option.&nbsp; I can only speak from past =
experience.</span><o:p></o:p></p>

<p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;
margin-left:.5in'><span =
style=3D'font-size:11.0pt;color:#1F497D'>&nbsp;</span><o:p></o:p></p>

<p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;
margin-left:.5in'><span style=3D'font-size:11.0pt;color:#1F497D'>But, if =
it is a
mandate for your environment, hopefully I helped point out some reasons =
why an
ADC can still provide some significant benefit.</span><o:p></o:p></p>

<p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;
margin-left:.5in'><span =
style=3D'font-size:11.0pt;color:#1F497D'>&nbsp;</span><o:p></o:p></p>

<p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;
margin-left:.5in'><span style=3D'font-size:11.0pt;color:#1F497D'>Good =
luck!</span><o:p></o:p></p>

<p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;
margin-left:.5in'><span =
style=3D'font-size:11.0pt;color:#1F497D'>&nbsp;</span><o:p></o:p></p>

<div>

<table class=3DMsoNormalTable border=3D0 cellpadding=3D0 width=3D425 =
style=3D'width:318.75pt;
 margin-left:.5in'>
 <tr>
  <td colspan=3D5 style=3D'padding:.75pt .75pt .75pt .75pt'>
  <p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'><b><span
  style=3D'font-size:10.0pt;color:#1F497D'>KJ (Ken) Salchow, =
Jr.</span></b><span
  style=3D'font-size:10.0pt;color:#1F497D'> | Manager, Technical =
Marketing</span><o:p></o:p></p>
  </td>
 </tr>
 <tr style=3D'min-height:9.0pt'>
  <td width=3D86 style=3D'width:64.25pt;padding:.75pt .75pt .75pt =
.75pt;min-height:9.0pt'>
  <p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;
  line-height:9.0pt'><b><span style=3D'font-size:7.5pt;color:#333333'>D
  651.423.1133</span></b><o:p></o:p></p>
  </td>
  <td width=3D86 style=3D'width:64.25pt;padding:.75pt .75pt .75pt =
.75pt;min-height:9.0pt'>
  <p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;
  line-height:9.0pt'><b><span style=3D'font-size:7.5pt;color:#333333'>M
  612.868.1258</span></b><o:p></o:p></p>
  </td>
  <td width=3D86 style=3D'width:64.25pt;padding:.75pt .75pt .75pt =
.75pt;min-height:9.0pt'>
  <p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;
  line-height:9.0pt'><b><span style=3D'font-size:7.5pt;color:#333333'>P
  206.272.5555</span></b><o:p></o:p></p>
  </td>
  <td width=3D86 style=3D'width:64.25pt;padding:.75pt .75pt .75pt =
.75pt;min-height:9.0pt'>
  <p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;
  line-height:9.0pt'><b><span style=3D'font-size:7.5pt;color:#333333'>F
  206.272.5555</span></b><o:p></o:p></p>
  </td>
  <td width=3D70 style=3D'width:52.75pt;padding:.75pt .75pt .75pt =
.75pt;min-height:9.0pt'>
  <p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;
  line-height:9.0pt'><b><span style=3D'font-size:7.5pt;color:#333333'><a
  href=3D"http://www.f5.com/" target=3D"_blank"><span =
style=3D'color:#333333'>www.f5.com</span></a></span></b><o:p></o:p></p>
  </td>
 </tr>
</table>

<p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;
margin-left:.5in'><span =
style=3D'font-size:11.0pt;color:#1F497D'>&nbsp;</span><o:p></o:p></p>

<p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;
margin-left:.5in'><span =
style=3D'font-size:11.0pt;color:#1F497D'>&nbsp;</span><o:p></o:p></p>

<div>

<div style=3D'border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt =
0in 0in 0in'>

<p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;
margin-left:1.0in'><b><span =
style=3D'font-size:10.0pt'>From:</span></b><span
style=3D'font-size:10.0pt'> <a href=3D"mailto:[email protected]"
target=3D"_blank">[email protected]</a> [mailto:<a
href=3D"mailto:[email protected]" =
target=3D"_blank">[email protected]</a>]
<b>On Behalf Of </b>Van Ceylon, David<br>
<b>Sent:</b> Thursday, February 18, 2010 1:01 PM<br>
<b>To:</b> 'Load Balancing Mailing List'<br>
<b>Subject:</b> [load balancing] SSL w/ PCI best =
practices</span><o:p></o:p></p>

</div>

</div>

<div>

<div>

<p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;
margin-left:1.0in'>&nbsp;<o:p></o:p></p>

<p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;
margin-left:1.0in'><span style=3D'font-size:10.0pt'>Hello &#8211; =
</span><o:p></o:p></p>

<p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;
margin-left:1.0in'><span =
style=3D'font-size:10.0pt'>&nbsp;</span><o:p></o:p></p>

<p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;
margin-left:1.0in'><span style=3D'font-size:10.0pt'>I have a question =
regarding
the use of SSL while trying to maintain PCI compliance. &nbsp;If a load
balancer/SSL accelerator is handling SSL, what advantage is that in =
terms of
SSL offload if we must re-encrypt back to the servers?&nbsp; This =
essentially limits
the load balancer to URI inspection and distributing traffic.&nbsp; =
There seems
to be no advantage to handling Certs (other than wildcard) or =
de-encryption.
&nbsp;Forgive my ignorance but I&#8217;m looking for basic best =
practices in
this situation.</span><o:p></o:p></p>

<p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;
margin-left:1.0in'><span =
style=3D'font-size:10.0pt'>&nbsp;</span><o:p></o:p></p>

<p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;
margin-left:1.0in'><span =
style=3D'font-size:10.0pt'>Thanks!</span><o:p></o:p></p>

<p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;
margin-left:1.0in'><span =
style=3D'font-size:10.0pt'>&nbsp;</span><o:p></o:p></p>

<p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;
margin-left:1.0in'><span style=3D'font-size:10.0pt'>David =
VanCeylon</span><o:p></o:p></p>

<p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;
margin-left:1.0in'>&nbsp;<o:p></o:p></p>

<p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;
margin-left:1.0in'>&nbsp;<o:p></o:p></p>

<div style=3D'margin-left:.5in'>

<div class=3DMsoNormal align=3Dcenter =
style=3D'margin-left:.5in;text-align:center'>

<hr size=3D2 width=3D"100%" align=3Dcenter>

</div>

</div>

<p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;
margin-left:1.0in'><span style=3D'font-size:7.5pt;color:gray'>This =
communication
is the property of Qwest and may contain confidential or<br>
privileged information. Unauthorized use of this communication is =
strictly<br>
prohibited and may be unlawful. If you have received this =
communication<br>
in error, please immediately notify the sender by reply e-mail and =
destroy<br>
all copies of the communication and any =
attachments.</span><o:p></o:p></p>

</div>

</div>

</div>

</div>

</div>

<p class=3DMsoNormal =
style=3D'mso-margin-top-alt:0in;margin-right:0in;margin-bottom:
12.0pt;margin-left:.5in'><br>
_______________________________________________<br>
lb-l mailing list<br>
<a href=3D"mailto:[email protected]">[email protected]</a><br>
<a href=3D"http://vegan.net/mailman/listinfo/lb-l" =
target=3D"_blank">http://vegan.net/mailman/listinfo/lb-l</a><br>
Searchable Archive: <a href=3D"http://vegan.net/lb/archive" =
target=3D"_blank">http://vegan.net/lb/archive</a><br>
<a href=3D"http://lbdigest.com" =
target=3D"_blank">http://lbdigest.com</a> Load
Balancing Digest<br>
<a href=3D"http://lbwiki.com" target=3D"_blank">http://lbwiki.com</a> =
Load
Balancing Wiki<o:p></o:p></p>

</div>

<p class=3DMsoNormal style=3D'margin-left:.5in'><br>
<br clear=3Dall>
<br>
-- <br>
Bill Blackford<br>
Network Engineer <br>
<br>
Logged into reality and abusing my sudo privileges.....<o:p></o:p></p>

</div>

</div>

</body>

</html>

------=_NextPart_001_079A_01CAB53F.AE685280--

------=_NextPart_000_0799_01CAB53F.AE685280
Content-Type: application/x-pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"

MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIIzjCCAlYw
ggG/oAMCAQICEEgb315xx3HUwgzZMb1Lyl0wDQYJKoZIhvcNAQEFBQAwYjELMAkGA1UEBhMCWkEx
JTAjBgNVBAoTHFRoYXd0ZSBDb25zdWx0aW5nIChQdHkpIEx0ZC4xLDAqBgNVBAMTI1RoYXd0ZSBQ
ZXJzb25hbCBGcmVlbWFpbCBJc3N1aW5nIENBMB4XDTA5MDgyNjIzNTc1MloXDTEwMDgyNjIzNTc1
MlowQjEfMB0GA1UEAxMWVGhhd3RlIEZyZWVtYWlsIE1lbWJlcjEfMB0GCSqGSIb3DQEJARYQay5z
YWxjaG93QGY1LmNvbTCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAry5h0di1dpSX3iunEOj5
yhbkKQwF8+4MnRaGp5LhwITm+/2K977gkxd2FqBho+iC0sMCxbFDarMawqOITQuzoW/0VqcOyNrW
Zh/L6dRQOSFIjJAz4eGAtuohC5N8oRdV+l1Zb8UcOua11YBPcOLAgD94AOcALm0DFlwaTsQi8pcC
AwEAAaMtMCswGwYDVR0RBBQwEoEQay5zYWxjaG93QGY1LmNvbTAMBgNVHRMBAf8EAjAAMA0GCSqG
SIb3DQEBBQUAA4GBAJDs8XatGqIVTw6NkEdNOxwIaxbQI8JU8NZcGIc42DbX/TsUXR8CAdFJ640Q
pXke6ldn8I01pEPEIlUWri2zNrEVgSuHGizrt3qGn8hHU4hmO3vdhHqXWeowalRZMDA8P9oMAhjK
2j9EfnxJ8N5USl8/JEbayDFnjFvBU7DOi08PMIIDLTCCApagAwIBAgIBADANBgkqhkiG9w0BAQQF
ADCB0TELMAkGA1UEBhMCWkExFTATBgNVBAgTDFdlc3Rlcm4gQ2FwZTESMBAGA1UEBxMJQ2FwZSBU
b3duMRowGAYDVQQKExFUaGF3dGUgQ29uc3VsdGluZzEoMCYGA1UECxMfQ2VydGlmaWNhdGlvbiBT
ZXJ2aWNlcyBEaXZpc2lvbjEkMCIGA1UEAxMbVGhhd3RlIFBlcnNvbmFsIEZyZWVtYWlsIENBMSsw
KQYJKoZIhvcNAQkBFhxwZXJzb25hbC1mcmVlbWFpbEB0aGF3dGUuY29tMB4XDTk2MDEwMTAwMDAw
MFoXDTIwMTIzMTIzNTk1OVowgdExCzAJBgNVBAYTAlpBMRUwEwYDVQQIEwxXZXN0ZXJuIENhcGUx
EjAQBgNVBAcTCUNhcGUgVG93bjEaMBgGA1UEChMRVGhhd3RlIENvbnN1bHRpbmcxKDAmBgNVBAsT
H0NlcnRpZmljYXRpb24gU2VydmljZXMgRGl2aXNpb24xJDAiBgNVBAMTG1RoYXd0ZSBQZXJzb25h
bCBGcmVlbWFpbCBDQTErMCkGCSqGSIb3DQEJARYccGVyc29uYWwtZnJlZW1haWxAdGhhd3RlLmNv
bTCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEA1GnX1LCUZFtx6UfYDFG26nKRsIRefS0Nj3sS
34UldSh0OkIsYyeflXtL734Zhx2G6qPduc6WZBrCFG5ErHzmj+hND3EfQDimAKOHePb5lIZererA
Xnbr2RSjXW56fAylS1V/Bhkpf56aJtVquzgkCGqYx7Hao5iR/Xnb5VrEHLkCAwEAAaMTMBEwDwYD
VR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQQFAAOBgQDH7JJ+Tvj1lqVnYiqk8E0RYNBvjWBYYawm
u1I1XAjPMPuoSpaKH2JCI4wXD/S6ZJwXrEcp352YXtJsYHFcoqzceePnbgBHH7UNKOgCneSa/RP0
ptl8sfjcXyMmCZGAc9AUG95DqYMl8uacLxXK/qarigd1iwzdUYRr5PjRzneigTCCAz8wggKooAMC
AQICAQ0wDQYJKoZIhvcNAQEFBQAwgdExCzAJBgNVBAYTAlpBMRUwEwYDVQQIEwxXZXN0ZXJuIENh
cGUxEjAQBgNVBAcTCUNhcGUgVG93bjEaMBgGA1UEChMRVGhhd3RlIENvbnN1bHRpbmcxKDAmBgNV
BAsTH0NlcnRpZmljYXRpb24gU2VydmljZXMgRGl2aXNpb24xJDAiBgNVBAMTG1RoYXd0ZSBQZXJz
b25hbCBGcmVlbWFpbCBDQTErMCkGCSqGSIb3DQEJARYccGVyc29uYWwtZnJlZW1haWxAdGhhd3Rl
LmNvbTAeFw0wMzA3MTcwMDAwMDBaFw0xMzA3MTYyMzU5NTlaMGIxCzAJBgNVBAYTAlpBMSUwIwYD
VQQKExxUaGF3dGUgQ29uc3VsdGluZyAoUHR5KSBMdGQuMSwwKgYDVQQDEyNUaGF3dGUgUGVyc29u
YWwgRnJlZW1haWwgSXNzdWluZyBDQTCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAxKY8VXNV
+065yplaHmjAdQRwnd/p/6Me7L3N9VvyGna9fww6YfK/Uc4B1OVQCjDXAmNaLIkVcI7dyfArhVqq
P3FWy688Cwfn8R+RNiQqE88r1fOCdz0Dviv+uxg+B79AgAJk16emu59l0cUqVIUPSAR/p7bRPGEE
QB5kGXJgt/sCAwEAAaOBlDCBkTASBgNVHRMBAf8ECDAGAQH/AgEAMEMGA1UdHwQ8MDowOKA2oDSG
Mmh0dHA6Ly9jcmwudGhhd3RlLmNvbS9UaGF3dGVQZXJzb25hbEZyZWVtYWlsQ0EuY3JsMAsGA1Ud
DwQEAwIBBjApBgNVHREEIjAgpB4wHDEaMBgGA1UEAxMRUHJpdmF0ZUxhYmVsMi0xMzgwDQYJKoZI
hvcNAQEFBQADgYEASIzRUIPqCy7MDaNmrGcPf6+svsIXoUOWlJ1/TCG4+DYfqi2fNi/A9BxQIJNw
PP2t4WFiw9k6GX6EsZkbAMUaC4J0niVQlGLH2ydxVyWN3amcOY6MIE9lX5Xa9/eH1sYITq726jTl
EBpbNU1341YheILcIRk13iSx0x1G/11fZU8xggL4MIIC9AIBATB2MGIxCzAJBgNVBAYTAlpBMSUw
IwYDVQQKExxUaGF3dGUgQ29uc3VsdGluZyAoUHR5KSBMdGQuMSwwKgYDVQQDEyNUaGF3dGUgUGVy
c29uYWwgRnJlZW1haWwgSXNzdWluZyBDQQIQSBvfXnHHcdTCDNkxvUvKXTAJBgUrDgMCGgUAoIIB
2DAYBgkqhkiG9w0BCQMxCwYJKoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEPFw0xMDAyMjQxNjU0MDRa
MCMGCSqGSIb3DQEJBDEWBBQZW/finjVETHu3aVleyxYcBr7YJzBnBgkqhkiG9w0BCQ8xWjBYMAoG
CCqGSIb3DQMHMA4GCCqGSIb3DQMCAgIAgDANBggqhkiG9w0DAgIBQDAHBgUrDgMCBzANBggqhkiG
9w0DAgIBKDAHBgUrDgMCGjAKBggqhkiG9w0CBTCBhQYJKwYBBAGCNxAEMXgwdjBiMQswCQYDVQQG
EwJaQTElMCMGA1UEChMcVGhhd3RlIENvbnN1bHRpbmcgKFB0eSkgTHRkLjEsMCoGA1UEAxMjVGhh
d3RlIFBlcnNvbmFsIEZyZWVtYWlsIElzc3VpbmcgQ0ECEEgb315xx3HUwgzZMb1Lyl0wgYcGCyqG
SIb3DQEJEAILMXigdjBiMQswCQYDVQQGEwJaQTElMCMGA1UEChMcVGhhd3RlIENvbnN1bHRpbmcg
KFB0eSkgTHRkLjEsMCoGA1UEAxMjVGhhd3RlIFBlcnNvbmFsIEZyZWVtYWlsIElzc3VpbmcgQ0EC
EEgb315xx3HUwgzZMb1Lyl0wDQYJKoZIhvcNAQEBBQAEgYCn5sHSgDkiO/87DKcub1HDxrXNr2jE
KPfIjtAppZxLw1vCXFWu5kQVJc6ygtKfJG81UlF6qx4priCD6WY9cZIDiikZl+goIFRGSYr2gljQ
DmlooBq0XIj3oXmQljNwHRpcq3nolCXKpXzdKqKr8KW8YZDa2pXctFsfJQgzJrQB2AAAAAAAAA==

------=_NextPart_000_0799_01CAB53F.AE685280--

--===============1201749382==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
lb-l mailing list
[email protected]
http://vegan.net/mailman/listinfo/lb-l
Searchable Archive: http://vegan.net/lb/archive
http://lbdigest.com Load Balancing Digest
http://lbwiki.com Load Balancing Wiki

--===============1201749382==--