6 ms·
Kestrel needs a reverse proxy in front of it for SSL termination etc. https://docs.microsoft.com/en-us/aspnet/core/fundamentals/servers/?view=aspnetcore-2.1&tab
by davidgl 8y ago
Kestrel needs a reverse proxy in front of it for SSL termination etc. https://docs.microsoft.com/en-us/aspnet/core/fundamentals/servers/?view=aspnetcore-2.1&tabs=aspnetcore2x https://docs.microsoft.com/en-us/aspnet/core/fundamentals/se...
- benaadams 8y agoDoesn't need on for SSL; needs a reverse proxy if you want to do port sharing (many apps on port 80/443 switched by host header) or Windows Auth. You can also build your reverse proxy using Kestrel. Though IIS is more battle tested so they may be using that as front line server for such a high profile service as Bing
- cm2187 8y agoIs it even wise to design a system that uses un-encrypted backend traffic? The Snowden revelations did demonstrate that intelligence services are snooping on those.
- benaadams 8y agoNot over an actual network; but localhost or in-process it should be fine? Though the in-process IIS hosting is ASP.NET Core 2.2 as it got bumped from the 2.1 release https://github.com/aspnet/IISIntegration/issues/878 https://github.com/aspnet/IISIntegration/issues/878
- cm2187 8y agook but then it is not much of a load balancer.
- benaadams 8y agoMeant for port sharing; multiple apps or subdomains switching either on host header or path; as you can't have multiple processes listening on the same port (80/443) on the same machine. Or changing which is run based on the path
- OldSchoolJohnny 8y agoThat's no longer a requirement with the latest release of .net core.