2 Aug 2006 02:21
SSL certs on proxy pool?
Vincent Fox <vbfox <at> ucdavis.edu>
2006-08-02 00:21:17 GMT
2006-08-02 00:21:17 GMT
Wondering how folks handle SSL certs? Assuming you have 2 or more Perdition units in a load-balancer. Do you get wildcard certs? The only other way that immediately occurs is to use a load-balancer that can handle SSL processing. I can see how that should work okay with sessions that are 995/pops or 993/imaps. But what about sessions that are TLS? They start out plaintext on 110 or 143 and switch using STARTTLS. Doesn't the loadbalancer need to acts as a sort of app proxy to handle that shift? Maybe I'm overthinking it but it seems like this would be more complicated. -- -- Perdition - http://www.vergenet.net/linux/perdition/ To UNSUBSCRIBE, email to lisa <at> vergenet.net, with a body: unsubscribe perdition-users your-email-address <at> some.domain where "your-email-address <at> some.domain" is YOUR email address.
Of course, there are many bells and whistles offered with
"content switching" products (hardware SSL offload, sticky sessions
etc.), but you just need Layer 3 load balancing. Round-robin or
RSS Feed