Re: [fw-wiz] Using SSL accelerators in firewalls

From: Ryan Russell (ryan@securityfocus.com)
Date: 07/17/02


From: Ryan Russell <ryan@securityfocus.com>
To: Darren Reed <darrenr@reed.wattle.id.au>
Date: Wed Jul 17 12:57:01 2002

On Wed, 17 Jul 2002, Darren Reed wrote:

> There would seem to be a growing trend in using SSL accelerators not
> next to the web server but attached to a firewall so that it isn't
> https traffic that passes through but http.
>
> To me this screams out "bad design" as the end-to-end encryption is
> lost in the process and the security of transactions eroded.

So? Where is the bad guy? If the traffic is still encrypted when it goes
past him, then the crypto is still doing its job. The obvious change is
that there's now this small length of wire where the traffic isn't
encrypted, somewhere on your DMZ. This means that an attacker who has
compromised a machine on your DMZ can probably sniff the web traffic. THe
machine that is mostly likely to be compromised is your web server, and
even if it's not, they can likely sniff the traffic between the web server
and the DB anyway, which is more to the point if they are trying to steal
stuff you need SSL to protect.

I.e. in my opinion, worrying about that short bit of unencrypted traffic
is worrying about a smaller problem when there are larger ones to worry
about. (I consider a hostile on my DMZ a worse problem that having my
traffic sniffed.)

> What do others think? Is this becoming a "done thing" that is more
> and more acceptable to corporates or is this just an isolated thing?

It's probably a done deal for anyone who has a significant amount of SSL
traffic to do. It takes the CPU laod off the webservers, the SSL box
probably includes the HTTP load balancing feature you need anyway, and
your get your NIDS functionality back.

                                        Ryan



Relevant Pages

  • RE: Automatically Redirecting HTTP to HTTPS
    ... if I set the site to require SSL ... then users can't access the site via http or https. ... is installed on ISA). ... >> We have a Web server on our LAN behind ISA. ...
    (microsoft.public.windows.server.sbs)
  • Re: ISA 2004 Server Errors
    ... Tunneling SSL Through a WWW Proxy ... CONNECT is really a lower-level function than the rest of the HTTP methods, ... Through ISA Server ...
    (microsoft.public.isa)
  • Re: RWW with no https
    ... What you cannot normally do is configure an HTTP SSL listeners to redirect traffic based on HTTP headers. ... Or dump Kerio Mail Server since you have the same capabilities in Exchange;-) ... > port but going to port 8080. ...
    (microsoft.public.windows.server.sbs)
  • Re: SSL cert in ISA 2006
    ... protocol (HTTP, SMRP, POP3, IMAP, etc.) to provide session-level encryption. ... What is the purpose of SSL used in ISA for? ...
    (microsoft.public.isa.configuration)
  • Re: Redirect https to http Exchange 2007
    ... I took off require SSL on the /OWA dir and i can get to ... it by http and https, but the redirect to https isnt working if i force ssl ... /OWA vdir but the redirect to SSL isnt working, ...
    (microsoft.public.exchange.admin)