Re: SSL Reverse Proxy

From: Vic Parat (NSS) (vic.parat_at_nssecurity.com)
Date: 04/28/03

  • Next message: Rivera Alonso, David: "RE: SSL Reverse Proxy"
    To: "Andrea Cogliati" <AndreaC@gotech.it>, <security-basics@securityfocus.com>
    Date: Mon, 28 Apr 2003 10:23:52 -0700
    
    

    F5 networks covers this nicely with their various products (BigIp,3DNS)
    depending on the type of redirection you want to do. www.f5.com. Can be
    pricey.

    ----- Original Message -----
    From: "Andrea Cogliati" <AndreaC@gotech.it>
    To: <security-basics@securityfocus.com>
    Sent: Monday, April 28, 2003 4:06 AM
    Subject: SSL Reverse Proxy

    Guys,

    We are looking for a reverse-proxy supporting both http and https,
    capable of terminating the client connections and redirecting the
    requests based on URL (something like MS ISA); caching would be nice to
    have but, definitely, not mandatory; must run on OpenBSD and/or Linux.

    We already know the security implications of this approach. We basically
    need to share the same SSL certificate and the same DNS name between two
    different servers. That is, https://mydomain.com/appA and
    https://mydomain.com/appB, where requests to the first URL will be
    handled by server A, and those to the latter by server B. Any hints?

    Thank you in advance for any advice.

    Andrea

    ---------------------------------------------------------------------------
    Attend Black Hat Briefings & Training Europe, May 12-15 in Amsterdam, the
    world's premier event for IT and network security experts. The two-day
    Training features 6 hand-on courses on May 12-13 taught by professionals.
    The two-day Briefings on May 14-15 features 24 top speakers with no vendor
    sales pitches. Deadline for the best rates is April 25. Register today to
    ensure your place. http://www.securityfocus.com/BlackHat-security-basics
    ----------------------------------------------------------------------------

    ---------------------------------------------------------------------------
    FastTrain has your solution for a great CISSP Boot Camp. The industry's most
    recognized corporate security certification track, provides a comprehensive
    prospectus based upon the core principle concepts of security. This ALL INCLUSIVE curriculum utilizes lectures, case studies and true hands-on utilization
    of pertinent security tools. For a limited time you can enter for a chance
    to win one of the latest technological innovations, the SEGWAY HT.
    Log onto http://www.securityfocus.com/FastTrain-security-basics
    ----------------------------------------------------------------------------


  • Next message: Rivera Alonso, David: "RE: SSL Reverse Proxy"

    Relevant Pages

    • RE: [Full-Disclosure] RE: MS SQL WORM IS DESTROYING INTERNET BLOCK PORT 1434!
      ... Subject: RE: MS SQL WORM IS DESTROYING INTERNET ... Perhaps some of the .edu admins need to ... >basic network design concepts and security. ... But the admins whose networks got hit *still* didn't ...
      (Full-Disclosure)
    • Re: << SBS News this week 7/25/2004>>
      ... > Homeland security has become a key issue in the US. ... > the Virginia Cyber-Crime Strike Force. ... > Fifteen employees at Los Alamos National Laboratory ... > networks is urgently required but agreed to work ...
      (microsoft.public.backoffice.smallbiz2000)
    • Re: << SBS News this week 7/25/2004>>
      ... > Homeland security has become a key issue in the US. ... > the Virginia Cyber-Crime Strike Force. ... > Fifteen employees at Los Alamos National Laboratory ... > networks is urgently required but agreed to work ...
      (microsoft.public.windows.server.sbs)
    • Re: [Full-disclosure] A Botted Fortune 500 a Day
      ... I believe security of an organisation is orthogonal to the number of ... >> Fortune 500 companies have more employees than some ISPs have customers. ... > compromises on their internal networks. ...
      (Bugtraq)
    • Re: [Full-Disclosure] DCOM RPC exploit (dcom.c)
      ... > There are at UTD, and I know there are at many other campuses. ... by virtue of the title "Adjunct Information Security ... Now go click all 5000 computers we have to take care of. ... There were networks that were ...
      (Full-Disclosure)