4 ms·
On my load balancers it is more like 5-10%. Not terrible, but not trivial either. Also, it multiplies throughout the environment. If you are dealing with PII or
by workermonkey 12y ago
On my load balancers it is more like 5-10%. Not terrible, but not trivial either. Also, it multiplies throughout the environment. If you are dealing with PII or financials, everything needs to be encrypted on the wire.
Load balancer decrypts, looks at headers, decides what to do, re-encrypts, down to the app tier, decrypt, respond encrypted, etc. I'm not saying that is a bad thing, but that's why some people get cranky.
Somewhat unrelated, compressed headers in HTTP 2.0 makes sense if you only think about the browser, it saves 'repeated' information. The problem is the LB has to decrypt them every time anyways, so someone still have to do the work, it just isn't on the wire. Server push on the other hand could be awesome for performance (pre-cache the resources for the next page in a flow) but also has the potential for abuse.
- magicalist 12y ago> If you are dealing with PII or financials, everything needs to be encrypted on the wire. Well I hope you'd be doing that even without HTTP/2...
- tracker1 12y agoWhy not just run unencrypted behind the load balancer? Unless they're on wholely different networks, it shouldn't be needed.. SSL termination makes sense at a load balancer, reverse proxy, etc.
- workermonkey 12y agoPCI.
- stephen_g 12y agoLike how Google used to do it? http://cdn01.androidauthority.net/wp-content/uploads/2014/06/SSL-Added-and-Removed-Here.jpg http://cdn01.androidauthority.net/wp-content/uploads/2014/06...