
gabster at lelutin
Jul 29, 2013, 11:12 AM
Post #8 of 8
(107 views)
Permalink
|
|
Re: Varnish pipe through for SSL requests
[In reply to]
|
|
Hi there, On 29/07/13 09:24 AM, David Harrigan wrote: > Our approach is to terminate using Pound (http://www.apsis.ch/pound), > then to pass on to Varnish. It works *wonderfully* well and is super > easy to configure. Please note that if it is setup that way with the infrastructure that the OP described (e.g. caching needs to be on another server than the web server), then it means that your clients who are using an encrypted connection to your site will have their traffic pass over the internet unencrypted between the caching node and the web server. that's usually very bad security-wise because as a client if you use encryption, you expect that any sensitive data passed to a site stays encrypted over the network and that only that website can gain access to the sensitive data. if traffic goes through the net unencrypted, then that assumption is completely false. in that case, you can either: * consider moving your web hosting to your other server that hosts varnish, if you feel up to the challenge of managing your own web server. * or find some way to reencrypt traffic between the caching and the web server. for the 2nd option, the easiest would be to setup an encryption tunnel (like a VPN) between both servers and use the tunnel exclusively to communicate between varnish and the web server. > On 26 July 2013 02:22, Norberto Meijome <numard [at] gmail > <mailto:numard [at] gmail>> wrote: > > You should be able to with modproxy.. We terminate on nginx which > acts as proxy for clusters of app servers and varnishes...just tell > nginx to connect to varnish over http. > > On 26/07/2013 5:27 AM, "Yari Shima" <yarishima42 [at] googlemail > <mailto:yarishima42 [at] googlemail>> wrote: > > Hi Reinis, > > Thanks for your awnser. > But can't I use apache to listen on port 443 on my root server > and with > mod_proxy pipr the traffic through to my managed server? -- Gabriel Filion
|