Re: SSL w/ PCI best practices
David Coulthart <[email protected]> Wed, 24 Feb 2010 14:23:21 -0500
| Newsgroups | gmane.comp.programming.load-balancing.general |
|---|---|
| Message-ID | <[email protected]> |
On Feb 24, 2010, at 11:54 AM, Kenneth Salchow wrote: > Bill=97 > > Thanks for the verification. I know this was a HUGE security debate = > back in 2000 when we started doing the ssl termination, but I think = > over the years people have come to agree on the fact that as long s = > the traffic stays within a secure zone, with limited electronic and = > physical access, that it is ok. Would folks be willing to share any practical documents describing how = to create "secure zones?" I'm currently working on a project to = replace our existing load balancer and would really like to push for = SSL termination (mainly so I can get the network management benefits = of using SNAT). However, I'm concerned I'll face resistance from our = application, systems & security groups regarding the risks of SSL = termination. Thanks, Dave Coulthart _______________________________________________ lb-l mailing list [email protected] http://vegan.net/mailman/listinfo/lb-l Searchable Archive: http://vegan.net/lb/archive http://lbdigest.com Load Balancing Digest http://lbwiki.com Load Balancing Wiki