Re: SSL w/ PCI best practices

Ali Abbas <[email protected]> Wed, 24 Feb 2010 21:10:33 +0100
Newsgroups gmane.comp.programming.load-balancing.general
Message-ID <[email protected]>
--===============1691221105==
Content-Type: multipart/alternative; boundary=00151747b64a6c8f1804805e4390

--00151747b64a6c8f1804805e4390
Content-Type: text/plain; charset=windows-1252
Content-Transfer-Encoding: quoted-printable

Hi,

On Wed, Feb 24, 2010 at 8:23 PM, David Coulthart <[email protected]> wrote=
:

> On Feb 24, 2010, at 11:54 AM, Kenneth Salchow wrote:
>
>> Bill=97
>>
>> Thanks for the verification.  I know this was a HUGE security debate bac=
k
>> in 2000 when we started doing the ssl termination, but I think over the
>> years people have come to agree on the fact that as long s the traffic s=
tays
>> within a secure zone, with limited electronic and physical access, that =
it
>> is ok.
>>
>
> Would folks be willing to share any practical documents describing how to
> create "secure zones?"


Have a look at the PCI DSS whitepapers  (just google, you will find plenty)=
.

"Restricted zones" - that's subjective to each network environment....
restricting access is just a part... you need to develop a plan to handle
rising vulnerabilities, perform routine pen-tests etc... surveillance using
IDS/IPS etc...

Cheers,

Ali
--
Ali Abbas
Blog: http://alouche.net

--00151747b64a6c8f1804805e4390
Content-Type: text/html; charset=windows-1252
Content-Transfer-Encoding: quoted-printable

Hi,<br><br><div class=3D"gmail_quote">On Wed, Feb 24, 2010 at 8:23 PM, Davi=
d Coulthart <span dir=3D"ltr">&lt;<a href=3D"mailto:[email protected]">dav=
[email protected]</a>&gt;</span> wrote:<br><blockquote class=3D"gmail_quote" =
style=3D"border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8=
ex; padding-left: 1ex;">

<div class=3D"im">On Feb 24, 2010, at 11:54 AM, Kenneth Salchow wrote:<br>
<blockquote class=3D"gmail_quote" style=3D"border-left: 1px solid rgb(204, =
204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">
Bill=97<br>
<br>
Thanks for the verification. =A0I know this was a HUGE security debate back=
 in 2000 when we started doing the ssl termination, but I think over the ye=
ars people have come to agree on the fact that as long s the traffic stays =
within a secure zone, with limited electronic and physical access, that it =
is ok.<br>


</blockquote>
<br></div>
Would folks be willing to share any practical documents describing how to c=
reate &quot;secure zones?&quot;=A0</blockquote><div>=A0<br>Have a look at t=
he PCI DSS whitepapers=A0 (just google, you will find plenty).<br><br>&quot=
;Restricted zones&quot; - that&#39;s subjective to each network environment=
.... restricting access is just a part... you need to develop a plan to han=
dle rising vulnerabilities, perform routine pen-tests etc... surveillance u=
sing IDS/IPS etc...<br>

<br>Cheers,<br><br>Ali<br clear=3D"all">--<br>Ali Abbas<br>Blog: <a href=3D=
"http://alouche.net">http://alouche.net</a><br></div></div>

--00151747b64a6c8f1804805e4390--

--===============1691221105==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
lb-l mailing list
[email protected]
http://vegan.net/mailman/listinfo/lb-l
Searchable Archive: http://vegan.net/lb/archive
http://lbdigest.com Load Balancing Digest
http://lbwiki.com Load Balancing Wiki

--===============1691221105==--