SSL offloading - Sitefinity CMS Setup and maintenance (2024)

PREREQUISITES: SSL offloading sends the process of encoding and decoding SSL requests to a separate device. Therefore, you must:

  • Acquire an SSL certificate from an authorized vendor, install, and configure it.
  • Have anadditional SSL offloading device that is specifically designed to perform SSL acceleration and termination.

SSL offloading moves SSL encoding and decoding functions away from busy webservers to specialized devices that are better equipped to handle CPU-intensive SSL calculations.
This allows the webservers to dedicate important CPU resources to other application processing tasks, which can improve performance.

RECOMMENDATION:We recommend usingSSL offloading only in case you have a lot of HTTPS requests.

NOTE: If you are using Network Load Balancing, the load balancer can perform this function. For more information, seeLoad balancing.

The following chart illustrates a setup with an SSL offloader:

SSL offloading - Sitefinity CMS Setup and maintenance (1)

Configure Sitefinity CMS to know that SSL requests will be offloaded:

  1. Navigate to Administration » Settings » Advanced » System » SSL Offloading.
  2. Select EnableSslOffloading.
  3. In HttpHeaderFieldName, enter the same HTTP header field name, as the one used by your SSL offloading device.
    The reverse proxy (load balancer) communicates with a webserver usingonly unencrypted HTTP. Therefore, even if the request to the reverse proxy is encrypted HTTPS, you must specify the unencrypted HTTP header field name that will identifythe originating protocol of the HTTP request.
    The default value isX-Forwarded-Proto, which is the most commonly used by SSL offloading devices.
  4. In HttpHeaderFieldValue, leave the default value ofhttps
    The HTTPS header value indicates that the traffic from the client to the reverse proxy is encrypted. If you do not set this value or the abovementioned header, it will indicate that traffic from the client to the reverse proxy is not encrypted.
  5. Save your changes.

IMPORTANT: Your SSL offloading device must be set with the same HTTP header field name and HTTP value as the ones that you have entered in Sitefinity CMS. When the traffic must be encrypted between the reverse proxy and the client, before rerouting, the SSL offloading device must remove or replaceany headers with above field name. Otherwise, a client can imitate the header field name and value with the malicious intent to present encrypted traffic as nonencrypted.

SSL offloading - Sitefinity CMS Setup and maintenance (2024)

FAQs

SSL offloading - Sitefinity CMS Setup and maintenance? ›

SSL offloading is the process of removing the SSL-based encryption from incoming traffic to relieve a web server of the processing burden of decrypting and/or encrypting traffic sent via SSL. The processing is offloaded to a separate device designed specifically for SSL acceleration or SSL termination.

What is SSL offloading? ›

SSL offloading is the process of removing the SSL-based encryption from incoming traffic to relieve a web server of the processing burden of decrypting and/or encrypting traffic sent via SSL. The processing is offloaded to a separate device designed specifically for SSL acceleration or SSL termination.

How do I disable SSL Sitefinity? ›

Click Administration » Settings » Advanced. In the treeview, click System » Site URL Settings. Select Remove ssl when the page does not require it checkbox. Click Save changes.

What is the difference between SSL decryption and SSL offloading? ›

One line explanation. SSL Bridging: The Load Balancer/Proxy decrypts incoming HTTPS traffic and re-encrypts it before forwarding it to the backend server. SSL Offloading (also known as SSL Termination): The Load Balancer/Proxy decrypts incoming HTTPS traffic and sends it to the backend server without encryption.

What is SSL in CMS? ›

SSL: Secure Sockets Layer

SSL is standard technology for securing an internet connection by encrypting data sent between a website and a browser (or between two servers). It prevents hackers from seeing or stealing any information transferred, including personal or financial data.

How to setup SSL offloading? ›

Navigate to Administration » Settings » Advanced » System » SSL Offloading. Select EnableSslOffloading. In HttpHeaderFieldName, enter the same HTTP header field name, as the one used by your SSL offloading device. The reverse proxy (load balancer) communicates with a webserver using only unencrypted HTTP.

What is the difference between SSL pass through and offloading? ›

SSL offloading (aka SSL termination): The Load Balancer decrypts incoming HTTPS traffic, and sends it to the backend server unencrypted. SSL passthrough: The Load Balancer does not decrypt incoming HTTPS traffic, and sends it to the backend server 'as is'.

How do I remove SSL from my website? ›

Deleting SSL certificates
  1. Go to your console's security menu. For more information, see Navigating to devices.
  2. From the Security menu, select SSL > Certificates.
  3. From the Actions menu, select Delete for the wanted SSL certificate.
  4. Click Yes to delete the SSL certificate.

How do I disable SSL settings? ›

Disable SSL Certificate Verification for an environment
  1. Open the API Client UI.
  2. Click on the Environments pane of the sidebar.
  3. Select your environment of choice.
  4. Click on the Settings tab.
  5. Use the Certificate Verification dropdown to disable or enable SSL verification.

How do I turn off auto SSL? ›

To do this, you can go through and disable AutoSSL for an individual cPanel account with the following steps:
  1. Log into WHM as root.
  2. Go to Home >> SSL/TLS >> Manage AutoSSL.
  3. Go to Manage Users.
  4. From there, you can select "Disable AutoSSL" on the user of your choice.
Aug 21, 2020

What is SSL offloading in Citrix? ›

One excellent feature of Citrix NetScaler is SSL Offload. To configure SSL offloading, you must enable SSL processing on the NetScaler appliance and configure an SSL based virtual server that will intercept SSL traffic, decrypt the traffic, and forward it to a service that is bound to the virtual server.

How do I know if SSL decryption is enabled? ›

Procedure. Navigate to https://ssl-proxy.opendnstest.com. A page advising if your request was successfully proxied or not will display. If the test page indicates that you are not currently using SSL decryption, check to make sure the identity you're using has SSL decryption enabled in the policy that applies to it.

What are three reasons for excluding a site from SSL decryption? ›

For traffic (IP addresses, users, URL categories, services, and even entire zones) that you choose not to decrypt, Create a Policy-Based Decryption Exclusion. Reasons that sites break decryption technically include pinned certificates, client authentication, incomplete certificate chains, and unsupported ciphers.

How does SSL work step by step? ›

How an SSL connection is established
  1. The client sends a request to the server for a secure session. ...
  2. The client receives the server's X. ...
  3. The client authenticates the server, using a list of known certificate authorities.
  4. The client generates a random symmetric key and encrypts it using server's public key.

Why is SSL mandatory? ›

In short: SSL keeps internet connections secure and prevents criminals from reading or modifying information transferred between two systems. When you see a padlock icon next to the URL in the address bar, that means SSL protects the website you are visiting.

Do I need SSL on my website? ›

To run a successful business website, you need an SSL certificate to prevent traffic interruption. Even if you don't collect any information from your website visitors, your website requires an SSL certificate to prevent customers from getting a pop-up that indicates your website is unsecured.

Should use SSL be on or off? ›

Extra protection is essential to ensure that none of this sensitive data is intercepted while in transit between your iPhone and an app or a website. So only dealing with sites and apps with SSL certificates installed is essential.

What happens if I turn off SSL? ›

Disabling SSL can create a security exposure where a malicious user within the network can attack the system.

What does clearing SSL do? ›

Clearing the SSL state eliminates the problems of caching certificates since it wipes out the cache. Doing this shouldn't be necessary in day-to-day computing, since resetting your computer or, in some cases, closing your browser, will also clear your SSL state.

What is the purpose of SSL termination? ›

SSL termination or SSL offloading decrypts and verifies data on the load balancer instead of the application server. Spared of having to organize incoming connections, the server can prioritize on other tasks like loading web pages. This helps increase server speed.

Top Articles
Find out Why Cortisol Is So Controversial When It Comes to Weight Loss
Dow 30 Stocks List Today • Dogs of the Dow
Penn Foster 1098 T Form
The 15 Best Places for Cinema in Amsterdam
Craigslist Cincinati
Suzie Q Breeding Mount
Account Now Login In
Autorcm
Https://Eaxcis.allstate.com
Skroch Funeral Home
Towson Transcript
Best Food Near Detroit Airport
Violent Night Showtimes Near Amc Fashion Valley 18
Medical conditions and pregnancy | Information
Vidant My Chart Login
Guilford County Mugshots Zone
Cities Within 1 Hour Of Me
Salisbury Post Crime News
Lynn Gruson
oremus Bible Browser
Varsity Competition Results 2022
48 Hours Season 35 Episodes
How to Find the Subdomains of a Domain | Geekflare
About Blank Games Unblocked Minecraft
What is Password-Based Authentication?
A Proven Plan for Financial Success | RamseySolutions.com
Craigslist Portland Cars And Trucks By Owner
Phoenix Hotel ab 84 €. Hotels in London - KAYAK
Gina's Pizza Port Charlotte Fl
Forza Horizon 5: 8 Best Cars For Rally Racing
Sites Like Av.nyuu
Raley Scrubs - Midtown
Thisassondeck
55 Farmer-Approved Recipes
2003 Chevrolet Corvette Z06 Coupe On for sale - Portland, OR - craigslist
Ixl Buffsci
1964 1 2 Mustang For Sale Craigslist
Product Support Centre & Downloads | Kyocera Document Solutions
Costco Gas Kingman Az
Loopnet Properties For Sale
Lawrence Ks Police Scanner
Solar Nails Port Lavaca
Pwc Trader Florida
Pensacola Tattoo Studio 2 Reviews
Flixtor Nu Not Working
Berks County Court Schedule
Jacob I. Taylor, M.D., MPH - Urology Clinics of North Texas
Craigslist Fort Madison Iowa
T.j. Maxx And Homegoods Woburn Photos
Meggen Nut
Boat Trader Minnesota
Craigslist Domestic Job
Latest Posts
Article information

Author: Saturnina Altenwerth DVM

Last Updated:

Views: 5726

Rating: 4.3 / 5 (44 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Saturnina Altenwerth DVM

Birthday: 1992-08-21

Address: Apt. 237 662 Haag Mills, East Verenaport, MO 57071-5493

Phone: +331850833384

Job: District Real-Estate Architect

Hobby: Skateboarding, Taxidermy, Air sports, Painting, Knife making, Letterboxing, Inline skating

Introduction: My name is Saturnina Altenwerth DVM, I am a witty, perfect, combative, beautiful, determined, fancy, determined person who loves writing and wants to share my knowledge and understanding with you.