Re: SSL server and certificate for more than 1 host

Andrew Cook <[email protected]> Tue, 15 Jun 2010 15:49:20 +1000
Newsgroups gmane.comp.programming.load-balancing.general
Message-ID <[email protected]>
--===============0679157717==
Content-Type: multipart/alternative; boundary=0016367d6dec6e4bc704890b2a35

--0016367d6dec6e4bc704890b2a35
Content-Type: text/plain; charset=windows-1252
Content-Transfer-Encoding: quoted-printable

Hi Vitor,



I=92ve seen a  few of the follow up comments, though most have discussed th=
e
issue of certificate reuse/ sharing between hosts (i.e. wild card certs).
However as I re-read your message, the issue is one of persistence? Single
VIP, multiple real servers? Or multiple VIPs+ real servers? Are you actuall=
y
using the SSL card in the 2424SSL?



The 2424-SSL is an interesting piece of work, as the SSL module is
essentially a separate functional module housed within the 2424 case. It ha=
s
the ability to provide load-balancing functions directly on the SSL card,
without any particular reliance on the LB functions of the 2424 itself. You
can configure this via the SSL menus including persistence/ LB metrics.
 Essentially you setup a VIP on the 2424 LB to send SSL to the SSL card, an=
d
then (optionally) set up LB  on the SSL card itself.



Or you can also hook the decrypted traffic back into the main 2424 for LB
there. i.e. you use the SSL function to decrypt the SSL sessions, and
re-present the sessions to the main 2424 and then use cookie-based
persistence, hashing, etc from within the 2424 LB functions, including
URL-LB, etc. In my view, the 24242 LB functions were always much more
sophisticated at L4-L7, while the LB functions of the SSL card (ASA,
iSD-SSL, etc) were always a little more rudimentary.



So the answer is that it really depends on how you have your 2424SSL setup.
Care to post a config of both the 2424 and the SSL card? And a clearer
description of the problem?



While I=92ve always really liked the Alteons (lots of nostalgia there...),
later ADCs such as F5 LTM and NetScalers have truly integrated SSL. Adding
SSL processing on top of a robust LB config is (almost) as simple as tickin=
g
a  config box...



Cheers,



Andrew



Andrew Cook *-* Director
*Smartworx - *creating synergies between networks and applications.
65 Hume Street, Crows Nest. NSW. 2065 Australia

t: +612 9016 2880  f: +612 9016 2881  m: +61 419 253 347
email: [email protected]    web: www.smartworx.net.au







*From:* [email protected] [mailto:[email protected]] *On Behalf O=
f
*Jose Vitor Barreiro
*Sent:* Monday, 14 June 2010 7:20 PM
*To:* [email protected]
*Subject:* [load balancing] SSL server and certificate for more than 1 host



Hi,



Does anyone have experience with one AAS2424-SSL using one SSL certificate
for more than one host?



I have a costumer that has focused on the ssl certificate five hosts and
with this situation we are having problems with persistence for SSL traffic
(traffic  between the SSL module and http servers).





Best Regards



Vitor barreiro







*AVISO DE CONFIDENCIALIDADE*: Este e-mail e quaisquer ficheiros inform=E1ti=
cos
com ele transmitidos s=E3o confidenciais e destinados ao conhecimento e uso
exclusivo do respectivo destinat=E1rio, n=E3o podendo o conte=FAdo dos mesm=
os ser
alterado. Caso tenha recebido este e-mail indevidamente, queira informar de
imediato o remetente e proceder =E0 destrui=E7=E3o da mensagem.

*CONFIDENTIALITY WARNING*: This e-mail and any files transmitted with it ar=
e
confidential and intended solely for the use of the individual or entity to
whom they are addressed. Their contents may not be altered. If you have
received this e-mail in error please notify the sender and destroy it
immediately.

 *P** **Antes de imprimir este mail, pense bem se tem mesmo que o fazer.
Proteja o meio ambiente.*

No virus found in this incoming message.
Checked by AVG - www.avg.com
Version: 9.0.829 / Virus Database: 271.1.1/2936 - Release Date: 06/14/10
05:45:00

--0016367d6dec6e4bc704890b2a35
Content-Type: text/html; charset=windows-1252
Content-Transfer-Encoding: quoted-printable

<html>

<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Diso-8859-=
1">
<meta name=3D"Generator" content=3D"Microsoft Word 12 (filtered medium)">
<style>
<!--
 /* Font Definitions */
 @font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
@font-face
	{font-family:Webdings;
	panose-1:5 3 1 2 1 5 9 6 7 3;}
 /* Style Definitions */
 p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
p
	{mso-style-priority:99;
	mso-margin-top-alt:auto;
	margin-right:0cm;
	mso-margin-bottom-alt:auto;
	margin-left:0cm;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";}
span.EmailStyle17
	{mso-style-type:personal;
	font-family:"Calibri","sans-serif";
	color:windowtext;}
span.mediumtext1
	{mso-style-name:medium_text1;}
span.EmailStyle21
	{mso-style-type:personal-reply;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page WordSection1
	{size:612.0pt 792.0pt;
	margin:70.85pt 3.0cm 70.85pt 3.0cm;}
div.WordSection1
	{page:WordSection1;}
-->
</style>

</head>

<body lang=3D"EN-AU" link=3D"blue" vlink=3D"purple">

<div class=3D"WordSection1">

<p class=3D"MsoNormal"><span style=3D"color:#1F497D">Hi Vitor,</span></p>

<p class=3D"MsoNormal"><span style=3D"color:#1F497D">=A0</span></p>

<p class=3D"MsoNormal"><span style=3D"color:#1F497D">I=92ve seen a=A0 few o=
f the
follow up comments, though most have discussed the issue of certificate reu=
se/
sharing between hosts (i.e. wild card certs). However as I re-read your mes=
sage,
the issue is one of persistence? Single VIP, multiple real servers? Or mult=
iple
VIPs+ real servers? Are you actually using the SSL card in the 2424SSL?</sp=
an></p>

<p class=3D"MsoNormal"><span style=3D"color:#1F497D">=A0</span></p>

<p class=3D"MsoNormal"><span style=3D"color:#1F497D">The 2424-SSL is an int=
eresting
piece of work, as the SSL module is essentially a separate functional modul=
e housed
within the 2424 case. It has the ability to provide load-balancing function=
s
directly on the SSL card, without any particular reliance on the LB functio=
ns of
the 2424 itself. You can configure this via the SSL menus including
persistence/ LB metrics. =A0Essentially you setup a VIP on the 2424 LB to s=
end
SSL to the SSL card, and then (optionally) set up LB =A0on the SSL card its=
elf.</span></p>

<p class=3D"MsoNormal"><span style=3D"color:#1F497D">=A0</span></p>

<p class=3D"MsoNormal"><span style=3D"color:#1F497D">Or you can also hook t=
he
decrypted traffic back into the main 2424 for LB there. i.e. you use the SS=
L
function to decrypt the SSL sessions, and re-present the sessions to the ma=
in
2424 and then use cookie-based persistence, hashing, etc from within the 24=
24 LB
functions, including URL-LB, etc. In my view, the 24242 LB functions were
always much more sophisticated at L4-L7, while the LB functions of the SSL =
card
(ASA, iSD-SSL, etc) were always a little more rudimentary.</span></p>

<p class=3D"MsoNormal"><span style=3D"color:#1F497D">=A0</span></p>

<p class=3D"MsoNormal"><span style=3D"color:#1F497D">So the answer is that =
it really
depends on how you have your 2424SSL setup. Care to post a config of both t=
he
2424 and the SSL card? And a clearer description of the problem?</span></p>

<p class=3D"MsoNormal"><span style=3D"color:#1F497D">=A0</span></p>

<p class=3D"MsoNormal"><span style=3D"color:#1F497D">While I=92ve always re=
ally
liked the Alteons (lots of nostalgia there...), later ADCs such as F5 LTM a=
nd NetScalers
have truly integrated SSL. Adding SSL processing on top of a robust LB conf=
ig
is (almost) as simple as ticking a =A0config box...</span></p>

<p class=3D"MsoNormal"><span style=3D"color:#1F497D">=A0</span></p>

<p class=3D"MsoNormal"><span style=3D"color:#1F497D">Cheers,</span></p>

<p class=3D"MsoNormal"><span style=3D"color:#1F497D">=A0</span></p>

<p class=3D"MsoNormal"><span style=3D"color:#1F497D">Andrew</span></p>

<p class=3D"MsoNormal"><span style=3D"color:#1F497D">=A0</span></p>

<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Ar=
ial&quot;,&quot;sans-serif&quot;;
color:black">Andrew Cook <b>-</b> Director</span><span style=3D"font-size:1=
0.0pt;
font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:#1F497D"><br>
<b>Smartworx=A0- </b></span><span style=3D"font-size:10.0pt;font-family:&qu=
ot;Arial&quot;,&quot;sans-serif&quot;;
color:blue">creating synergies between networks and applications.<br>
</span><span style=3D"font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;=
sans-serif&quot;;
color:gray">65 Hume Street, Crows Nest. NSW. 2065 Australia</span><span sty=
le=3D"font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;=
;color:#1F497D"></span></p>

<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Ar=
ial&quot;,&quot;sans-serif&quot;;
color:gray">t: +612 9016 2880=A0 f:=A0+612 9016 2881=A0 m:=A0+61
419 253 347<br>
email: </span><span style=3D"font-size:10.0pt;font-family:&quot;Arial&quot;=
,&quot;sans-serif&quot;;
color:#1F497D"><a href=3D"mailto:[email protected]"><span style=3D"col=
or:gray">[email protected]</span></a></span><span style=3D"font-size:1=
0.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:gray">=A0=
=A0=A0
web: </span><span style=3D"font-size:10.0pt;font-family:&quot;Arial&quot;,&=
quot;sans-serif&quot;;
color:#1F497D"><a href=3D"http://www.smartworx.net.au/"><span style=3D"colo=
r:gray">www.smartworx.net.au</span></a></span></p>

<p class=3D"MsoNormal"><span style=3D"color:#1F497D">=A0</span></p>

<p class=3D"MsoNormal"><span style=3D"color:#1F497D">=A0</span></p>

<p class=3D"MsoNormal"><span style=3D"color:#1F497D">=A0</span></p>

<div>

<div style=3D"border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0cm =
0cm 0cm">

<p class=3D"MsoNormal"><b><span lang=3D"EN-US" style=3D"font-size:10.0pt;fo=
nt-family:
&quot;Tahoma&quot;,&quot;sans-serif&quot;">From:</span></b><span lang=3D"EN=
-US" style=3D"font-size:10.0pt;
font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;"> <a href=3D"mailto:l=
[email protected]">[email protected]</a>
[mailto:<a href=3D"mailto:[email protected]">[email protected]</a=
>] <b>On Behalf Of </b>Jose Vitor Barreiro<br>
<b>Sent:</b> Monday, 14 June 2010 7:20 PM<br>
<b>To:</b> <a href=3D"mailto:[email protected]">[email protected]</a><br>
<b>Subject:</b> [load balancing] SSL server and certificate for more than 1
host</span></p>

</div>

</div>

<p class=3D"MsoNormal">=A0</p>

<p class=3D"MsoNormal"><span lang=3D"PT">Hi, </span></p>

<p class=3D"MsoNormal"><span lang=3D"PT">=A0</span></p>

<p class=3D"MsoNormal"><span lang=3D"EN-US">Does anyone have experience wit=
h one
AAS2424-SSL using one SSL certificate for more than one host?</span></p>

<p class=3D"MsoNormal"><span lang=3D"EN-US">=A0</span></p>

<p class=3D"MsoNormal"><span lang=3D"EN-US">I have a costumer that has focu=
sed on the
ssl certificate five hosts and with this situation we are having problems w=
ith
persistence for SSL traffic (traffic =A0between the SSL module and http
servers).</span></p>

<p class=3D"MsoNormal"><span lang=3D"EN-US">=A0</span></p>

<p class=3D"MsoNormal"><span class=3D"mediumtext1"><span style=3D"font-size=
:12.0pt;
font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:black;background=
:#EBEFF9">=A0</span></span></p>

<p class=3D"MsoNormal"><span class=3D"mediumtext1"><span lang=3D"EN-US" sty=
le=3D"font-size:
12.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:black;bac=
kground:#EBEFF9">Best
Regards</span></span></p>

<p class=3D"MsoNormal"><span class=3D"mediumtext1"><span lang=3D"EN-US" sty=
le=3D"font-size:
12.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:black;bac=
kground:#EBEFF9">=A0</span></span></p>

<p class=3D"MsoNormal"><span class=3D"mediumtext1"><span lang=3D"EN-US" sty=
le=3D"font-size:
12.0pt;font-family:&quot;Arial&quot;,&quot;sans-serif&quot;;color:black;bac=
kground:#EBEFF9">Vitor
barreiro</span></span></p>

<p class=3D"MsoNormal"><span lang=3D"EN-US">=A0</span></p>

<p class=3D"MsoNormal"><span lang=3D"EN-US">=A0</span></p>

<p class=3D"MsoNormal"><span lang=3D"EN-US">=A0</span></p>

<p style=3D"margin:0cm;margin-bottom:.0001pt;text-align:justify"><strong><s=
pan lang=3D"PT" style=3D"font-size:8.0pt;color:black">AVISO DE CONFIDENCIAL=
IDADE</span></strong><span lang=3D"PT" style=3D"font-size:8.0pt;color:black=
">: Este e-mail e quaisquer ficheiros
inform=E1ticos com ele transmitidos s=E3o confidenciais e destinados ao
conhecimento e uso exclusivo do respectivo destinat=E1rio, n=E3o podendo o =
conte=FAdo
dos mesmos ser alterado. Caso tenha recebido este e-mail indevidamente, que=
ira
informar de imediato o remetente e proceder =E0 destrui=E7=E3o da mensagem.=
 </span></p>

<p style=3D"mso-margin-top-alt:6.0pt;margin-right:0cm;margin-bottom:0cm;
margin-left:0cm;margin-bottom:.0001pt;text-align:justify"><strong><span lan=
g=3D"EN-GB" style=3D"font-size:8.0pt;color:black">CONFIDENTIALITY WARNING</=
span></strong><span lang=3D"EN-GB" style=3D"font-size:7.5pt;color:black">: =
This e-mail and any files
transmitted with it are confidential and intended solely for the use of the
individual or entity to whom they are addressed. Their contents may not be
altered. If you have received this e-mail in error please notify the sender=
 and
destroy it immediately.</span><span lang=3D"EN-GB" style=3D"font-size:7.5pt=
"></span></p>

<p style=3D"mso-margin-top-alt:6.0pt;margin-right:0cm;margin-bottom:0cm;
margin-left:0cm;margin-bottom:.0001pt;text-align:justify"><span lang=3D"EN-=
GB" style=3D"font-size:7.5pt">=A0</span><b><span lang=3D"EN-GB" style=3D"fo=
nt-size:24.0pt;
font-family:Webdings;color:green">P</span></b><strong><span lang=3D"EN-GB" =
style=3D"font-size:7.5pt">=A0</span></strong><strong><span lang=3D"PT" styl=
e=3D"font-size:7.5pt">Antes de imprimir este mail, pense bem se tem mesmo q=
ue
o fazer. Proteja o meio ambiente.</span></strong><span lang=3D"EN-GB" style=
=3D"font-size:7.5pt"></span></p>

<p><span style=3D"font-size:10.0pt;font-family:&quot;Arial&quot;,&quot;sans=
-serif&quot;">No virus
found in this incoming message.<br>
Checked by AVG - <a href=3D"http://www.avg.com">www.avg.com</a><br>
Version: 9.0.829 / Virus Database: 271.1.1/2936 - Release Date: 06/14/10
05:45:00</span></p>

</div>

</body>

</html>

--0016367d6dec6e4bc704890b2a35--

--===============0679157717==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
lb-l mailing list
[email protected]
http://vegan.net/mailman/listinfo/lb-l
Searchable Archive: http://vegan.net/lb/archive
http://lbdigest.com Load Balancing Digest
http://lbwiki.com Load Balancing Wiki

--===============0679157717==--