Re: SSL server and certificate for more than 1 host
Andrew Cook <[email protected]> Tue, 15 Jun 2010 15:49:20 +1000
| Newsgroups | gmane.comp.programming.load-balancing.general |
|---|---|
| Message-ID | <[email protected]> |
--===============0679157717== Content-Type: multipart/alternative; boundary=0016367d6dec6e4bc704890b2a35 --0016367d6dec6e4bc704890b2a35 Content-Type: text/plain; charset=windows-1252 Content-Transfer-Encoding: quoted-printable Hi Vitor, I=92ve seen a few of the follow up comments, though most have discussed th= e issue of certificate reuse/ sharing between hosts (i.e. wild card certs). However as I re-read your message, the issue is one of persistence? Single VIP, multiple real servers? Or multiple VIPs+ real servers? Are you actuall= y using the SSL card in the 2424SSL? The 2424-SSL is an interesting piece of work, as the SSL module is essentially a separate functional module housed within the 2424 case. It ha= s the ability to provide load-balancing functions directly on the SSL card, without any particular reliance on the LB functions of the 2424 itself. You can configure this via the SSL menus including persistence/ LB metrics. Essentially you setup a VIP on the 2424 LB to send SSL to the SSL card, an= d then (optionally) set up LB on the SSL card itself. Or you can also hook the decrypted traffic back into the main 2424 for LB there. i.e. you use the SSL function to decrypt the SSL sessions, and re-present the sessions to the main 2424 and then use cookie-based persistence, hashing, etc from within the 2424 LB functions, including URL-LB, etc. In my view, the 24242 LB functions were always much more sophisticated at L4-L7, while the LB functions of the SSL card (ASA, iSD-SSL, etc) were always a little more rudimentary. So the answer is that it really depends on how you have your 2424SSL setup. Care to post a config of both the 2424 and the SSL card? And a clearer description of the problem? While I=92ve always really liked the Alteons (lots of nostalgia there...), later ADCs such as F5 LTM and NetScalers have truly integrated SSL. Adding SSL processing on top of a robust LB config is (almost) as simple as tickin= g a config box... Cheers, Andrew Andrew Cook *-* Director *Smartworx - *creating synergies between networks and applications. 65 Hume Street, Crows Nest. NSW. 2065 Australia t: +612 9016 2880 f: +612 9016 2881 m: +61 419 253 347 email: [email protected] web: www.smartworx.net.au *From:* [email protected] [mailto:[email protected]] *On Behalf O= f *Jose Vitor Barreiro *Sent:* Monday, 14 June 2010 7:20 PM *To:* [email protected] *Subject:* [load balancing] SSL server and certificate for more than 1 host Hi, Does anyone have experience with one AAS2424-SSL using one SSL certificate for more than one host? I have a costumer that has focused on the ssl certificate five hosts and with this situation we are having problems with persistence for SSL traffic (traffic between the SSL module and http servers). Best Regards Vitor barreiro *AVISO DE CONFIDENCIALIDADE*: Este e-mail e quaisquer ficheiros inform=E1ti= cos com ele transmitidos s=E3o confidenciais e destinados ao conhecimento e uso exclusivo do respectivo destinat=E1rio, n=E3o podendo o conte=FAdo dos mesm= os ser alterado. Caso tenha recebido este e-mail indevidamente, queira informar de imediato o remetente e proceder =E0 destrui=E7=E3o da mensagem. *CONFIDENTIALITY WARNING*: This e-mail and any files transmitted with it ar= e confidential and intended solely for the use of the individual or entity to whom they are addressed. Their contents may not be altered. If you have received this e-mail in error please notify the sender and destroy it immediately. *P** **Antes de imprimir este mail, pense bem se tem mesmo que o fazer. Proteja o meio ambiente.* No virus found in this incoming message. Checked by AVG - www.avg.com Version: 9.0.829 / Virus Database: 271.1.1/2936 - Release Date: 06/14/10 05:45:00 --0016367d6dec6e4bc704890b2a35 Content-Type: text/html; charset=windows-1252 Content-Transfer-Encoding: quoted-printable <html> <head> <meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Diso-8859-= 1"> <meta name=3D"Generator" content=3D"Microsoft Word 12 (filtered medium)"> <style> <!-- /* Font Definitions */ @font-face {font-family:"Cambria Math"; panose-1:2 4 5 3 5 4 6 3 2 4;} @font-face {font-family:Calibri; panose-1:2 15 5 2 2 2 4 3 2 4;} @font-face {font-family:Tahoma; panose-1:2 11 6 4 3 5 4 4 2 4;} @font-face {font-family:Webdings; panose-1:5 3 1 2 1 5 9 6 7 3;} /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal {margin:0cm; margin-bottom:.0001pt; font-size:11.0pt; font-family:"Calibri","sans-serif";} a:link, span.MsoHyperlink {mso-style-priority:99; color:blue; text-decoration:underline;} a:visited, span.MsoHyperlinkFollowed {mso-style-priority:99; color:purple; text-decoration:underline;} p {mso-style-priority:99; mso-margin-top-alt:auto; margin-right:0cm; mso-margin-bottom-alt:auto; margin-left:0cm; font-size:12.0pt; font-family:"Times New Roman","serif";} span.EmailStyle17 {mso-style-type:personal; font-family:"Calibri","sans-serif"; color:windowtext;} span.mediumtext1 {mso-style-name:medium_text1;} span.EmailStyle21 {mso-style-type:personal-reply; font-family:"Calibri","sans-serif"; color:#1F497D;} .MsoChpDefault {mso-style-type:export-only; font-size:10.0pt;} @page WordSection1 {size:612.0pt 792.0pt; margin:70.85pt 3.0cm 70.85pt 3.0cm;} div.WordSection1 {page:WordSection1;} --> </style> </head> <body lang=3D"EN-AU" link=3D"blue" vlink=3D"purple"> <div class=3D"WordSection1"> <p class=3D"MsoNormal"><span style=3D"color:#1F497D">Hi Vitor,</span></p> <p class=3D"MsoNormal"><span style=3D"color:#1F497D">=A0</span></p> <p class=3D"MsoNormal"><span style=3D"color:#1F497D">I=92ve seen a=A0 few o= f the follow up comments, though most have discussed the issue of certificate reu= se/ sharing between hosts (i.e. wild card certs). However as I re-read your mes= sage, the issue is one of persistence? Single VIP, multiple real servers? Or mult= iple VIPs+ real servers? Are you actually using the SSL card in the 2424SSL?</sp= an></p> <p class=3D"MsoNormal"><span style=3D"color:#1F497D">=A0</span></p> <p class=3D"MsoNormal"><span style=3D"color:#1F497D">The 2424-SSL is an int= eresting piece of work, as the SSL module is essentially a separate functional modul= e housed within the 2424 case. It has the ability to provide load-balancing function= s directly on the SSL card, without any particular reliance on the LB functio= ns of the 2424 itself. You can configure this via the SSL menus including persistence/ LB metrics. =A0Essentially you setup a VIP on the 2424 LB to s= end SSL to the SSL card, and then (optionally) set up LB =A0on the SSL card its= elf.</span></p> <p class=3D"MsoNormal"><span style=3D"color:#1F497D">=A0</span></p> <p class=3D"MsoNormal"><span style=3D"color:#1F497D">Or you can also hook t= he decrypted traffic back into the main 2424 for LB there. i.e. you use the SS= L function to decrypt the SSL sessions, and re-present the sessions to the ma= in 2424 and then use cookie-based persistence, hashing, etc from within the 24= 24 LB functions, including URL-LB, etc. In my view, the 24242 LB functions were always much more sophisticated at L4-L7, while the LB functions of the SSL = card (ASA, iSD-SSL, etc) were always a little more rudimentary.</span></p> <p class=3D"MsoNormal"><span style=3D"color:#1F497D">=A0</span></p> <p class=3D"MsoNormal"><span style=3D"color:#1F497D">So the answer is that = it really depends on how you have your 2424SSL setup. Care to post a config of both t= he 2424 and the SSL card? And a clearer description of the problem?</span></p> <p class=3D"MsoNormal"><span style=3D"color:#1F497D">=A0</span></p> <p class=3D"MsoNormal"><span style=3D"color:#1F497D">While I=92ve always re= ally liked the Alteons (lots of nostalgia there...), later ADCs such as F5 LTM a= nd NetScalers have truly integrated SSL. Adding SSL processing on top of a robust LB conf= ig is (almost) as simple as ticking a =A0config box...</span></p> <p class=3D"MsoNormal"><span style=3D"color:#1F497D">=A0</span></p> <p class=3D"MsoNormal"><span style=3D"color:#1F497D">Cheers,</span></p> <p class=3D"MsoNormal"><span style=3D"color:#1F497D">=A0</span></p> <p class=3D"MsoNormal"><span style=3D"color:#1F497D">Andrew</span></p> <p class=3D"MsoNormal"><span style=3D"color:#1F497D">=A0</span></p> <p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:"Ar= ial","sans-serif"; color:black">Andrew Cook <b>-</b> Director</span><span style=3D"font-size:1= 0.0pt; font-family:"Arial","sans-serif";color:#1F497D"><br> <b>Smartworx=A0- </b></span><span style=3D"font-size:10.0pt;font-family:&qu= ot;Arial","sans-serif"; color:blue">creating synergies between networks and applications.<br> </span><span style=3D"font-size:10.0pt;font-family:"Arial","= sans-serif"; color:gray">65 Hume Street, Crows Nest. NSW. 2065 Australia</span><span sty= le=3D"font-size:10.0pt;font-family:"Arial","sans-serif"= ;color:#1F497D"></span></p> <p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:"Ar= ial","sans-serif"; color:gray">t: +612 9016 2880=A0 f:=A0+612 9016 2881=A0 m:=A0+61 419 253 347<br> email: </span><span style=3D"font-size:10.0pt;font-family:"Arial"= ,"sans-serif"; color:#1F497D"><a href=3D"mailto:[email protected]"><span style=3D"col= or:gray">[email protected]</span></a></span><span style=3D"font-size:1= 0.0pt;font-family:"Arial","sans-serif";color:gray">=A0= =A0=A0 web: </span><span style=3D"font-size:10.0pt;font-family:"Arial",&= quot;sans-serif"; color:#1F497D"><a href=3D"http://www.smartworx.net.au/"><span style=3D"colo= r:gray">www.smartworx.net.au</span></a></span></p> <p class=3D"MsoNormal"><span style=3D"color:#1F497D">=A0</span></p> <p class=3D"MsoNormal"><span style=3D"color:#1F497D">=A0</span></p> <p class=3D"MsoNormal"><span style=3D"color:#1F497D">=A0</span></p> <div> <div style=3D"border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0cm = 0cm 0cm"> <p class=3D"MsoNormal"><b><span lang=3D"EN-US" style=3D"font-size:10.0pt;fo= nt-family: "Tahoma","sans-serif"">From:</span></b><span lang=3D"EN= -US" style=3D"font-size:10.0pt; font-family:"Tahoma","sans-serif""> <a href=3D"mailto:l= [email protected]">[email protected]</a> [mailto:<a href=3D"mailto:[email protected]">[email protected]</a= >] <b>On Behalf Of </b>Jose Vitor Barreiro<br> <b>Sent:</b> Monday, 14 June 2010 7:20 PM<br> <b>To:</b> <a href=3D"mailto:[email protected]">[email protected]</a><br> <b>Subject:</b> [load balancing] SSL server and certificate for more than 1 host</span></p> </div> </div> <p class=3D"MsoNormal">=A0</p> <p class=3D"MsoNormal"><span lang=3D"PT">Hi, </span></p> <p class=3D"MsoNormal"><span lang=3D"PT">=A0</span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US">Does anyone have experience wit= h one AAS2424-SSL using one SSL certificate for more than one host?</span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US">=A0</span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US">I have a costumer that has focu= sed on the ssl certificate five hosts and with this situation we are having problems w= ith persistence for SSL traffic (traffic =A0between the SSL module and http servers).</span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US">=A0</span></p> <p class=3D"MsoNormal"><span class=3D"mediumtext1"><span style=3D"font-size= :12.0pt; font-family:"Arial","sans-serif";color:black;background= :#EBEFF9">=A0</span></span></p> <p class=3D"MsoNormal"><span class=3D"mediumtext1"><span lang=3D"EN-US" sty= le=3D"font-size: 12.0pt;font-family:"Arial","sans-serif";color:black;bac= kground:#EBEFF9">Best Regards</span></span></p> <p class=3D"MsoNormal"><span class=3D"mediumtext1"><span lang=3D"EN-US" sty= le=3D"font-size: 12.0pt;font-family:"Arial","sans-serif";color:black;bac= kground:#EBEFF9">=A0</span></span></p> <p class=3D"MsoNormal"><span class=3D"mediumtext1"><span lang=3D"EN-US" sty= le=3D"font-size: 12.0pt;font-family:"Arial","sans-serif";color:black;bac= kground:#EBEFF9">Vitor barreiro</span></span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US">=A0</span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US">=A0</span></p> <p class=3D"MsoNormal"><span lang=3D"EN-US">=A0</span></p> <p style=3D"margin:0cm;margin-bottom:.0001pt;text-align:justify"><strong><s= pan lang=3D"PT" style=3D"font-size:8.0pt;color:black">AVISO DE CONFIDENCIAL= IDADE</span></strong><span lang=3D"PT" style=3D"font-size:8.0pt;color:black= ">: Este e-mail e quaisquer ficheiros inform=E1ticos com ele transmitidos s=E3o confidenciais e destinados ao conhecimento e uso exclusivo do respectivo destinat=E1rio, n=E3o podendo o = conte=FAdo dos mesmos ser alterado. Caso tenha recebido este e-mail indevidamente, que= ira informar de imediato o remetente e proceder =E0 destrui=E7=E3o da mensagem.= </span></p> <p style=3D"mso-margin-top-alt:6.0pt;margin-right:0cm;margin-bottom:0cm; margin-left:0cm;margin-bottom:.0001pt;text-align:justify"><strong><span lan= g=3D"EN-GB" style=3D"font-size:8.0pt;color:black">CONFIDENTIALITY WARNING</= span></strong><span lang=3D"EN-GB" style=3D"font-size:7.5pt;color:black">: = This e-mail and any files transmitted with it are confidential and intended solely for the use of the individual or entity to whom they are addressed. Their contents may not be altered. If you have received this e-mail in error please notify the sender= and destroy it immediately.</span><span lang=3D"EN-GB" style=3D"font-size:7.5pt= "></span></p> <p style=3D"mso-margin-top-alt:6.0pt;margin-right:0cm;margin-bottom:0cm; margin-left:0cm;margin-bottom:.0001pt;text-align:justify"><span lang=3D"EN-= GB" style=3D"font-size:7.5pt">=A0</span><b><span lang=3D"EN-GB" style=3D"fo= nt-size:24.0pt; font-family:Webdings;color:green">P</span></b><strong><span lang=3D"EN-GB" = style=3D"font-size:7.5pt">=A0</span></strong><strong><span lang=3D"PT" styl= e=3D"font-size:7.5pt">Antes de imprimir este mail, pense bem se tem mesmo q= ue o fazer. Proteja o meio ambiente.</span></strong><span lang=3D"EN-GB" style= =3D"font-size:7.5pt"></span></p> <p><span style=3D"font-size:10.0pt;font-family:"Arial","sans= -serif"">No virus found in this incoming message.<br> Checked by AVG - <a href=3D"http://www.avg.com">www.avg.com</a><br> Version: 9.0.829 / Virus Database: 271.1.1/2936 - Release Date: 06/14/10 05:45:00</span></p> </div> </body> </html> --0016367d6dec6e4bc704890b2a35-- --===============0679157717== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ lb-l mailing list [email protected] http://vegan.net/mailman/listinfo/lb-l Searchable Archive: http://vegan.net/lb/archive http://lbdigest.com Load Balancing Digest http://lbwiki.com Load Balancing Wiki --===============0679157717==--