LiteSpeed Technologies
Download Download     Blog Blog     Wiki Wiki     Forum Forum     Store     Contact Contact    

Go Back   LiteSpeed Support Forums > LiteSpeed Web Server > Install/Configuration > https ?

Reply
 
Thread Tools Display Modes
  #11  
Old 05-04-2004, 01:48 PM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,583
Do you mind sharing the ssl accelerator hardware solution, I am very interested in how it works. Thanks. :-)

I still couldn't believe name based SSL vhost possible.
After reading the squid configuration options you posted and cf.data.pre in squid source code (version 3.0 and 2.5), I think that the client could only get the SSL certificate specified in the squid configuration, but not the SSL certificates used by the backend Apache and the backend Apache only received decrypted requests from squid.

If you don't mind, could you please PM me the SSL web sites configured in this way. I am really interested in such solution.

Thanks.
Reply With Quote
  #12  
Old 05-04-2004, 11:08 PM
xing xing is offline
LiteSpeed Staff
 
Join Date: Oct 2003
Location: Los Angeles, California
Posts: 380
Actually...BeerCan, are you interested in a cheap but high quality hardware SSL accelerator? I just happen to have 2. =)

1) Intel Netstructure 7280 XML Accelerator
( In reality, it's a http/tcp load balancer AND has builtin dual/2 PCI hardware crypto SSL cards for 600SSL per second)

2) Intel Netstructure 7110 - SSL only and it has one PCI hardware SSL card inside. Rated for 200 SSL/second.

Check out the specs at Intel and let me know if you are interested. You can reach me at xing@fictionpress.com.
Reply With Quote
  #13  
Old 05-14-2004, 06:49 AM
bogus bogus is offline
Member
 
Join Date: Dec 2003
Location: Brittany / France / Europe
Posts: 31
Quote:
Originally Posted by mistwang

I still couldn't believe name based SSL vhost possible.
They are not. Squid associates (ip,port) to certs, as can do LSWS or Apache directly. The exposed configuration allows to centralize all certs in case the backends are on remote machines. In that case, the link between proxy and backend is not (necessary) crypted.

The alternate port solution is not even an alternative to multiple IPs if your clients are corporate : firewalls usually do not allow alternatives to 443.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
PHP curl HTTPS does not work in chroot sofatime PHP 3 05-15-2007 05:51 AM
how to use control panel via HTTPS ? aww Install/Configuration 2 05-03-2007 06:06 PM
Add header when proxing zhesto Ruby/Rails 2 06-19-2006 10:55 PM
https connection errors/chained certificates issue SyNeo Install/Configuration 14 09-01-2005 08:35 AM


All times are GMT -7. The time now is 01:13 PM.



- Archive - Top
© Copyright 2003-2011 LiteSpeed Technologies, Inc. All rights reserved. Privacy Policy.