Hello and welcome to CertForums.co.uk, here we host free active certification forums with links to the best free resources for Microsoft's MCSA MCSE MCDBA Cisco's CCNA CCDA and CCNP, and CompTIA's A+ Network+ i-NET+ and Security+ certifications in the UK. If you wish to post or use other advanced features you will need to register first. Registration is absolutely free and takes only a few minutes to complete so sign up today!

If you have any problems with the registration process or your account login, please contact support

Go Back   CertForums > Computing Support Forums > Connectivity, Telecommunications & the Internet
Home Forums Register Search Today's Posts Mark Forums Read

SSL Overheads?

Post New ThreadReply
 
Thread Tools Display Modes
  #1  
Old 08-May-2008, 09:56 AM
garyb's Avatar
garyb garyb is offline
Valued Member
Posts: 153
Points: 24 garyb has between 1 & 100 points
Power: 5
None
Join Date: 27 Feb 2007
Location: Peterborough UK
Age: 40
WIP: MCSA 2003
SSL Overheads?

Hi,
I have several business sites all using SSLs from login screen down so all my sites are secured on 443. I am noticing some lag in the site on occasions which causes errors with .NET, we dont partuclary have high hits on the site but I guess the data side is quite hard. I am thinking of retaining the login page as SSL but after that dropping it to normal http to see if that will ease the overheads. Has anyone done this before, does it help? Also are there any serious security implications, we are regulated by FSA so have to be careful with data security..

Thanx

 
Reply With Quote
  #2  
Old 08-May-2008, 10:05 AM
dmarsh dmarsh is offline
Lifetime Member
Posts: 1,396
Points: 3240 dmarsh has over 3000 pointsdmarsh has over 3000 pointsdmarsh has over 3000 pointsdmarsh has over 3000 pointsdmarsh has over 3000 pointsdmarsh has over 3000 pointsdmarsh has over 3000 pointsdmarsh has over 3000 pointsdmarsh has over 3000 pointsdmarsh has over 3000 pointsdmarsh has over 3000 points
Power: 48
None
Join Date: 24 May 2007
Location: Hampshire
Age: 34
Certifications: One or two...
WIP: OU MST121
SSL should be used for all pages that contain sensitive information to protect from sniffing, this mainly includes pages with forms but could also include other pages if you have reports or other sensitive information. If its an intranet site or the information is not massively sensitive then you can just rely on the initial authorisation as you infer and take the risk of your packets getting captured.

You could consider SSL offload to another device or other tuning of your application, its not clear that SSL is the issue, it might be other parts of your infrastructure or the design of the app.


Last edited by dmarsh : 08-May-2008 at 10:20 AM.
 
Reply With Quote
  #3  
Old 08-May-2008, 11:15 AM
garyb's Avatar
garyb garyb is offline
Valued Member
Posts: 153
Points: 24 garyb has between 1 & 100 points
Power: 5
None
Join Date: 27 Feb 2007
Location: Peterborough UK
Age: 40
WIP: MCSA 2003
Hi & thanx for the reply.
I know the risks are high but I have been left with online apps developed by people with no regard to bandwidth or end user experience.. This is most noticeable with Ajax code when a user moves through the page quickly, the code cant catch up due to bandwidth limits [their end or mine], and eventually errors, not nice looking..

I do know the SSL is at least partly responsible, as our "pre-live" enviroment has no SSL and much better response times and very little errors, hence the reason I was thinking of implementing this in live servers. Another factor would be the hardware firewall with IDS/IPS and Gateway AV but the "pre-live" is behind this too..

Cheers

 
Reply With Quote
  #4  
Old 08-May-2008, 03:38 PM
hbroomhall hbroomhall is online now
Gold Member
Posts: 6,482
Points: 2188 hbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 points
Power: 92
None
Join Date: 08 Sep 2005
Location: Tunbridge Wells, Kent
Certifications: ECDL A+ Network+ i-Net+
WIP: Server+
I would say that it would be a somewhat underpowered machine that would be slowed noticeably by the encryption stuff.

And pre-live systems are often faster because the database is small and can be cached. Once it starts to grow then you hit the disk more often.

You could try more memory in there?

Harry.

 
Reply With Quote
Post New ThreadReply Spread this thread: Submit this thread to digg Submit this thread to del.icio.us


Go Back   CertForums > Computing Support Forums > Connectivity, Telecommunications & the Internet


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Publishing a Windows Server 2008 SSL VPN Server Using ISA 2006 Firewalls Mitzs Networking 1 04-Mar-2008 05:31 AM
SSL over Wireless Boyce Wireless Networking 2 24-Aug-2006 02:32 PM
FREE SSL and Digital Certificate Guide wagnerk Training & Development 0 07-Jun-2006 08:09 PM
Microsoft to Acquire Whale Communications, a Leading Provider of SSL VPN... Mr.Cheeks News 0 22-May-2006 04:40 PM
SSL Phoenix Problems, Suggestions & Comments 1 06-Sep-2005 08:49 AM


All times are GMT +1. The time now is 12:27 PM.

Powered by vBulletin® Version 3.6.11
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
CertForums.co.uk (C) copyright 2003-2007 All Rights Reserved. Content published on CertForums.co.uk requires permission for reprint.
Hosted by Lunarpages