SSL certs on proxy pool?

Vincent Fox vbfox at ucdavis.edu
Tue Aug 1 20:27:38 EDT 2006


Wondering how people deal with SSL certs with multiple frontends?

Do you put wildcard certs on the proxies and leave the SSL processing on
each unit?

Do you use an SSL-aware load-balancer and let it hold a cert for the
published hostname and do the heavy lifting?

If there's some 3rd way, I'm interested to hear it.

I'm not really clear what would happen on a load-balancer with TLS
switchovers, doesn't that imply the load-balancer has to be
application-aware not just like a hardware version of stunnel?



More information about the Info-cyrus mailing list