RE: SSL Reverse Proxy

From: Lucas Zaichkowsky (Lucas_at_dnsys.com)
Date: 04/29/03

  • Next message: Jordan Jesse - Toronto-MROC: "RE: Cable Vs. DSL"
    To: Andrea Cogliati <AndreaC@gotech.it>, security-basics@securityfocus.com
    Date: Tue, 29 Apr 2003 09:43:51 -0500
    
    

    You can install the certificate on both servers. The clients will only be
    looking at the host name along with the CA signature to determine validity.
    There's nothing tying a certificate to the IP.

    To do what you want with Microsoft ISA, you'll need to install the
    certificate and private key on the ISA server. Then, setup rules to forward
    traffic based off the URL.

    http://www.microsoft.com/technet/treeview/default.asp?url=/technet/prodtechn
    ol/isa/proddocs/isadocs/M_P_C_WebPubRule.asp

    If you want the SSL tunnel to go all the way to the web servers, you'll need
    to install the certificate and private key on both servers and find a load
    balancer that can redirect by URL. Personally, I don't know of a load
    balancer that does this, but I'd imagine that the feature isn't too unusual.

    -Lucas

    -----Original Message-----
    From: Andrea Cogliati [mailto:AndreaC@gotech.it]
    Sent: Monday, April 28, 2003 6:07 AM
    To: security-basics@securityfocus.com
    Subject: SSL Reverse Proxy

    Guys,

    We are looking for a reverse-proxy supporting both http and https,
    capable of terminating the client connections and redirecting the
    requests based on URL (something like MS ISA); caching would be nice to
    have but, definitely, not mandatory; must run on OpenBSD and/or Linux.

    We already know the security implications of this approach. We basically
    need to share the same SSL certificate and the same DNS name between two
    different servers. That is, https://mydomain.com/appA and
    https://mydomain.com/appB, where requests to the first URL will be
    handled by server A, and those to the latter by server B. Any hints?

    Thank you in advance for any advice.

    Andrea

    ---------------------------------------------------------------------------
    Attend Black Hat Briefings & Training Europe, May 12-15 in Amsterdam, the
    world's premier event for IT and network security experts. The two-day
    Training features 6 hand-on courses on May 12-13 taught by professionals.
    The two-day Briefings on May 14-15 features 24 top speakers with no vendor
    sales pitches. Deadline for the best rates is April 25. Register today to
    ensure your place. http://www.securityfocus.com/BlackHat-security-basics
    ----------------------------------------------------------------------------

    ---------------------------------------------------------------------------
    FastTrain has your solution for a great CISSP Boot Camp. The industry's most
    recognized corporate security certification track, provides a comprehensive
    prospectus based upon the core principle concepts of security. This ALL INCLUSIVE curriculum utilizes lectures, case studies and true hands-on utilization
    of pertinent security tools. For a limited time you can enter for a chance
    to win one of the latest technological innovations, the SEGWAY HT.
    Log onto http://www.securityfocus.com/FastTrain-security-basics
    ----------------------------------------------------------------------------


  • Next message: Jordan Jesse - Toronto-MROC: "RE: Cable Vs. DSL"

    Relevant Pages

    • Re: ?Expired Security Certif for MS Update
      ... MBSA should run fine on a new install. ... faith in the downloads I have, that used the expired certificate to get ... At the risk of sounding like an alien abductee, this security invasion ... Microsoft and signed by a CA that your computer trusts I would not worry ...
      (microsoft.public.windowsxp.security_admin)
    • Re: How do I protect a document out of design mode?
      ... My IT installators initially told me that they would install digital ... the macro security warnings. ... Select the certificate you want to add, ...
      (microsoft.public.word.vba.general)
    • Re: Suppressing security dialogs when app opens
      ... "Adding the above two keys to the install makes the runtime install ... I'm not comfortable altering the security mechanism of a machine without the user's knowledge ... ... Because a digital certificate you create yourself isn't issued by a formal certification authority, ... Microsoft Office will only trust a self-signed certificate on a computer that has the private key for that certificate ...
      (comp.databases.ms-access)
    • Re: Web Service Security
      ... The asmx file security is now set to 'ignore client certificates.' ... Viewing the certificate using the View Certificate button under directory ... you must install the certificate with a private key (usually ...
      (microsoft.public.dotnet.framework.aspnet.security)
    • Re: fc5: install everything?
      ... space or security for your servers. ... Any machine that we install and send out gets an install everything, ... Security, we turn off the extra unneeded services, mostly the install ... Too many of our customers are using obscure libraries for their applications, ...
      (Fedora)