Re: [fw-wiz] Using SSL accelerators in firewalls

From: Darren Reed (darrenr@reed.wattle.id.au)
Date: 07/17/02


From: Darren Reed <darrenr@reed.wattle.id.au>
To: firewall-wizards@honor.icsalabs.com
Date: Wed Jul 17 09:35:16 2002

In some email I received from Darren Reed, sie wrote:
>
> There would seem to be a growing trend in using SSL accelerators not
> next to the web server but attached to a firewall so that it isn't
> https traffic that passes through but http.

Let me ask this question another way.

If your bank was using one of these SSL accelerators and it was not
directly attached to the web server, but the "far side" of something
else so they could screen traffic and then pass your data through
some number of other things, unencrypted, would you use that bank's
Internet Banking service which used SSL encryption ?

If you had a choice between that and one which did the SSL encryption
on (or next to) the web server (lets assume all other security measures
are equal), which one would you choose, if you had the chance ?

Darren



Relevant Pages

  • [fw-wiz] Using SSL accelerators in firewalls
    ... There would seem to be a growing trend in using SSL accelerators not ... next to the web server but attached to a firewall so that it isn't ...
    (Firewall-Wizards)
  • Re: [fw-wiz] Using SSL accelerators in firewalls
    ... > There would seem to be a growing trend in using SSL accelerators not ... > next to the web server but attached to a firewall so that it isn't ... trust necessary to go to the border of a company and the ammount of trust ...
    (Firewall-Wizards)
  • RE: [fw-wiz] Using SSL accelerators in firewalls
    ... > If the bank has a SSL accelerator to <quote> screen traffic ... > design). ... >> There would seem to be a growing trend in using SSL accelerators not ... >> next to the web server but attached to a firewall so that it isn't ...
    (Firewall-Wizards)
  • Re: [fw-wiz] Using SSL accelerators in firewalls
    ... If the bank has a SSL accelerator to <quote> screen traffic and then pass your data through some number of other ... things, unencrypted, how is that different from decrypting it on the web server ... If your bank was using one of these SSL accelerators and it was not ...
    (Firewall-Wizards)
  • Re: [fw-wiz] Using SSL accelerators in firewalls
    ... > There would seem to be a growing trend in using SSL accelerators not ... > next to the web server but attached to a firewall so that it isn't ... In this respect you have to think about what the SSL security ...
    (Firewall-Wizards)