Re: SSL w/ PCI best practices
Ali Abbas <[email protected]> Wed, 24 Feb 2010 21:10:33 +0100
| Newsgroups | gmane.comp.programming.load-balancing.general |
|---|---|
| Message-ID | <[email protected]> |
--===============1691221105== Content-Type: multipart/alternative; boundary=00151747b64a6c8f1804805e4390 --00151747b64a6c8f1804805e4390 Content-Type: text/plain; charset=windows-1252 Content-Transfer-Encoding: quoted-printable Hi, On Wed, Feb 24, 2010 at 8:23 PM, David Coulthart <[email protected]> wrote= : > On Feb 24, 2010, at 11:54 AM, Kenneth Salchow wrote: > >> Bill=97 >> >> Thanks for the verification. I know this was a HUGE security debate bac= k >> in 2000 when we started doing the ssl termination, but I think over the >> years people have come to agree on the fact that as long s the traffic s= tays >> within a secure zone, with limited electronic and physical access, that = it >> is ok. >> > > Would folks be willing to share any practical documents describing how to > create "secure zones?" Have a look at the PCI DSS whitepapers (just google, you will find plenty)= . "Restricted zones" - that's subjective to each network environment.... restricting access is just a part... you need to develop a plan to handle rising vulnerabilities, perform routine pen-tests etc... surveillance using IDS/IPS etc... Cheers, Ali -- Ali Abbas Blog: http://alouche.net --00151747b64a6c8f1804805e4390 Content-Type: text/html; charset=windows-1252 Content-Transfer-Encoding: quoted-printable Hi,<br><br><div class=3D"gmail_quote">On Wed, Feb 24, 2010 at 8:23 PM, Davi= d Coulthart <span dir=3D"ltr"><<a href=3D"mailto:[email protected]">dav= [email protected]</a>></span> wrote:<br><blockquote class=3D"gmail_quote" = style=3D"border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8= ex; padding-left: 1ex;"> <div class=3D"im">On Feb 24, 2010, at 11:54 AM, Kenneth Salchow wrote:<br> <blockquote class=3D"gmail_quote" style=3D"border-left: 1px solid rgb(204, = 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;"> Bill=97<br> <br> Thanks for the verification. =A0I know this was a HUGE security debate back= in 2000 when we started doing the ssl termination, but I think over the ye= ars people have come to agree on the fact that as long s the traffic stays = within a secure zone, with limited electronic and physical access, that it = is ok.<br> </blockquote> <br></div> Would folks be willing to share any practical documents describing how to c= reate "secure zones?"=A0</blockquote><div>=A0<br>Have a look at t= he PCI DSS whitepapers=A0 (just google, you will find plenty).<br><br>"= ;Restricted zones" - that's subjective to each network environment= .... restricting access is just a part... you need to develop a plan to han= dle rising vulnerabilities, perform routine pen-tests etc... surveillance u= sing IDS/IPS etc...<br> <br>Cheers,<br><br>Ali<br clear=3D"all">--<br>Ali Abbas<br>Blog: <a href=3D= "http://alouche.net">http://alouche.net</a><br></div></div> --00151747b64a6c8f1804805e4390-- --===============1691221105== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ lb-l mailing list [email protected] http://vegan.net/mailman/listinfo/lb-l Searchable Archive: http://vegan.net/lb/archive http://lbdigest.com Load Balancing Digest http://lbwiki.com Load Balancing Wiki --===============1691221105==--