3 ms·
If you terminate SSL at the CDN, if you don't own the network and CDN, won't that leave your data open while in-transit between the CDN and the app servers? I'
by joevandyk 12y ago
If you terminate SSL at the CDN, if you don't own the network and CDN, won't that leave your data open while in-transit between the CDN and the app servers?
I'm using cloudfront and aws, reluctant to let cloudfront be the root CDN because of this. Anyone got any insight?
- rb2k_ 12y agoIs there a reason your CDN couldn't talk to your backend via SSL too?
- deleted 12y ago[deleted]
- firloop 12y agoCan't speak for Cloudfront, but I do know that Cloudflare has mitigated this problem. When you set up SSL, you have the option to force SSL from end to end. Of course, this approach means that SSL is terminated twice, once at the CDN and again when the user receives it, and this also relies on the assumption that you can trust Cloudflare with your data as it passes through their internal network.
- iancarroll 12y agoCloudFront can do this easily: http://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/SecureConnections.html http://docs.aws.amazon.com/AmazonCloudFront/latest/Developer...