Re: SSL termination for private domains
James Leavers
It sounds like we are in a similar situation to Carlo, i.e.
toggle quoted message
Show quoted text
- We have an external pair of LBs - These are used for SSL termination - We upload SSL certificates to the LBs for various domains, which point to the same VIP If something became available that would easily allow app developers / users to upload their own certificates, I too would happily move SSL termination from the LBs to gorouter, as it would mean one less automation workflow for us :-) On 21 September 2016 at 02:04:48, Shannon Coen (scoen(a)pivotal.io) wrote:
Carlo, Mike, others, Do you store certs in the LB config itself, or federate/offload TLS termination to some secure store? I'm thinking about storing user-provided certs in the Routing API and offering them to routers/LBs from there. Would we instead have to send the certs to some other proprietary system from where the router/LB would have to pull from? I've heard a few requests for integrating with systems that store the certs so that the routers don't have access to the keys. Shannon Coen Product Manager, Cloud Foundry Pivotal, Inc. On Tue, Sep 20, 2016 at 5:44 PM, Carlo Alberto Ferraris < carlo.ferraris(a)rakuten.com> wrote: Mike, |
|