RE: [squid-users] Reverse Proxy and Externally Generated Wildcard SSL Certificates

From: John Gardner <John.Gardner_at_southtyneside.gov.uk>
Date: Mon, 14 Feb 2011 16:31:10 +0000

>They may already be stored in PEM format then, the JUNEOS that runs on most Juniper devices was originally derived from FreeBSD and as such its SSL >implementation is likely based on OpenSSL (of course that's just a guess). I haven't worked on any Juniper devices myself, so I am of no help in >figuring out how to export them.
>If they were generated on the Juniper VPN appliance, is that device already doing HTTPS offloading for you? You might not get the desired benefit >moving that to a Squid proxy server if it is, perhaps just placing the proxy between the VPN appliance and the backend web server to utilize the cache >would give you the desired outcome without needing to move the SSL.

Dean

The Juniper box and the Squid box are on different segments of the DMZ and have different purposes... the Squid RP is /just/ for external users accessing Websites whereas the Juniper just handles external VPN users.

Thanks for the help anyway.

John

This email and any files transmitted with it are intended solely for the named recipient and may contain sensitive, confidential or protectively marked material up to the central government classification of ?RESTRICTED" which must be handled accordingly. If you have received this e-mail in error, please immediately notify the sender by e-mail and delete from your system, unless you are the named recipient (or authorised to receive it for the recipient) you are not permitted to copy, use, store, publish, disseminate or disclose it to anyone else.

E-mail transmission cannot be guaranteed to be secure or error-free as it could be intercepted, corrupted, lost, destroyed, arrive late or incomplete, or contain viruses and therefore the Council accept no liability for any such errors or omissions.

Unless explicitly stated otherwise views or opinions expressed in this email are solely those of the author and do not necessarily represent those of the Council and are not intended to be legally binding.

 

All Council network traffic and GCSX traffic may be subject to recording and/or monitoring in accordance with relevant legislation.

South Tyneside Council, Town Hall & Civic Offices, Westoe Road, South Shields, Tyne & Wear, NE33 2RL, Tel: 0191 427 1717, Website: www.southtyneside.info
Received on Mon Feb 14 2011 - 16:31:28 MST

This archive was generated by hypermail 2.2.0 : Tue Feb 15 2011 - 12:00:02 MST