{"id":7763,"date":"2018-10-25T16:42:04","date_gmt":"2018-10-25T20:42:04","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=7763"},"modified":"2024-05-20T16:25:18","modified_gmt":"2024-05-20T20:25:18","slug":"ssl-offloading-bridging-termination","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/ssl-offloading-bridging-termination\/","title":{"rendered":"SSL Offloading: What is it? How does it work? What are the benefits?"},"content":{"rendered":"<h2>What is SSL Offloading? Performing SSL at the Load Balancer level.<\/h2>\n<p>Today we\u2019re going to cover a question that comes up from time to time, and may seem especially foreign to people without an IT background: What is SSL offloading? We\u2019ll give a quick overview of what SSL offloading means, why you may want to do it and whether you should.<\/p>\n<p>One of the misnomers about SSL\/TLS and really with the way the internet works in general is that it\u2019s a 1:1 connection. A person\u2019s computer connects directly with a web server and communication goes directly from one to the other. In reality, it\u2019s far more complicated than that, with sometimes upwards of a dozen stops between end points.<\/p>\n<p>That\u2019s an important piece of information to keep in mind as we start getting into SSL offloading.<\/p>\n<p>So, what is SSL offloading and how does it work?<\/p>\n<p>Let\u2019s hash it out\u2026<span id=\"newline\"><\/span><\/p>\n<h2>What is SSL offloading?<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-medium wp-image-7767\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/bigstock-Server-Vector-Icon-On-White-Ba-245600212-300x300.jpg\" alt=\"SSL offloading\" width=\"300\" height=\"300\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/bigstock-Server-Vector-Icon-On-White-Ba-245600212-300x300.jpg 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/bigstock-Server-Vector-Icon-On-White-Ba-245600212-768x768.jpg 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/bigstock-Server-Vector-Icon-On-White-Ba-245600212-1024x1024.jpg 1024w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/bigstock-Server-Vector-Icon-On-White-Ba-245600212.jpg 1600w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/>Before <a href=\"https:\/\/www.thesslstore.com\/blog\/tls-1-3-approved\/\">TLS 1.3<\/a>, even before TLS 1.2, frankly, SSL\/TLS used to legitimately add latency to connections. That\u2019s what lent itself to the perception that SSL\/TLS slowed down websites. Ten years ago, that was the knock on SSL certificates. \u201cOh they slow down your site.\u201d And that was true at the time.<\/p>\n<p>It\u2019s not today, but in the past SSL\/TLS was considered a bit resource hungry. For starters, you have the SSL\/TLS handshake. <a href=\"https:\/\/www.thesslstore.com\/blog\/tls-1-3-handshake-tls-1-2\/\">It\u2019s been refined to where it\u2019s now a single roundtrip in TLS 1.3<\/a>, but <a href=\"https:\/\/www.thesslstore.com\/blog\/explaining-ssl-handshake\/\">before that it took several roundtrips<\/a>. Then, following the handshake, additional processing power had to be exerted <a href=\"https:\/\/www.thesslstore.com\/blog\/difference-encryption-hashing-salting\/\">to encrypt and decrypt the data being transmitted<\/a>. As the additional load from SSL\/TLS increases on the server, it\u2019s no longer able to process at full capacity.<\/p>\n<p>Again, <a href=\"https:\/\/www.thesslstore.com\/blog\/tls-1-3-everything-possibly-needed-know\/\">a lot of this has been cleaned up in TLS 1.3<\/a>, and <a href=\"https:\/\/www.thesslstore.com\/blog\/introduction-to-http2-hypertext-transfer-protocol\/\">HTTP\/2<\/a> &#8211; which requires the use of SSL\/TLS &#8211; helps to increase performance even more, but even with all of those improvements, SSL\/TLS can still add latency with higher volumes of traffic.<\/p>\n<p>So, what is SSL offloading? Well, to help offset the extra burden SSL\/TLS adds, you can spin up separate Application-Specific Integrated Circuit (ASIC) processers that are limited to just performing the functions required for SSL\/TLS, namely the handshake and the encryption\/decryption. This frees up processing power for the intended application or website. That\u2019s SSL offloading in a nutshell. Sometimes it\u2019s also called load balancing. You may hear the term load balancer tossed around. A load balancer is any device that helps improve the distribution of workloads across multiple resources, for instance distributing the SSL\/TLS workload to ASIC processors.<\/p>\n<span style=\"--tl-form-height-m:150.25px;--tl-form-height-t:121.4583px;--tl-form-height-d:121.4583px;\" class=\"tl-placeholder-f-type-shortcode_12753 tl-preload-form\"><span><\/span><\/span>\n<h2>What are the advantages of SSL offloading?<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-medium wp-image-7766 alignright\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/ssl-tss-300x243.jpg\" alt=\"SSL offloading\" width=\"300\" height=\"243\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/ssl-tss-300x243.jpg 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/ssl-tss.jpg 571w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/>SSL offloading has several benefits:<\/p>\n<ul>\n<li>It offloads additional tasks from your application servers so they can focus on their primary functions.<\/li>\n<li>It saves resources on those application servers.<\/li>\n<li>And, depending on what load balancer you\u2019re using, it can also help with <a href=\"https:\/\/www.thesslstore.com\/blog\/ssl-inspection\/\">HTTPS inspection<\/a>, reverse-proxying, cookie persistence, traffic regulation, etc.<\/li>\n<\/ul>\n<p>That last one is one of the most important: that in some cases SSL offloading can assist with traffic inspection. As important as encryption is, it has one major drawback: attackers can hide in your encrypted traffic. There\u2019s no shortage of high-profile exploits that have occurred as a result of attackers hiding in HTTPS traffic, <a href=\"https:\/\/www.thesslstore.com\/blog\/magecart-newegg-breach\/\">recently Magecart has been using HTTPS traffic to obfuscate the PCI it\u2019s been exfiltrating from various payment pages<\/a>.<\/p>\n<p>Being able to inspect HTTPS traffic becomes almost compulsory once your organization reaches a certain size, and one of the best ways to do that is to offload your SSL\/TLS processes.<\/p>\n<h2>How does SSL offloading work?<\/h2>\n<p>When we talk about SSL offloading there are two different ways to accomplish it:<\/p>\n<ul>\n<li>SSL Termination<\/li>\n<li>SSL Bridging<\/li>\n<\/ul>\n<p>Let\u2019s start with SSL termination first because it\u2019s a little bit simpler. Essentially it works this way, the proxy server or load balancer you use for the SSL offloading acts as the SSL terminator, which also acts as an edge device. When a client attempts to connect to a website, the client connects to the SSL terminator\u2014that connection is HTTPS. But the connection between the SSL terminator and the application server is via HTTP.<\/p>\n<p>Now, you may be asking how that doesn\u2019t cause problems with the browser, it\u2019s because the HTTP connection is taking place behind the scenes \u2013 on the internal network, protected by <a href=\"https:\/\/www.thesslstore.com\/blog\/what-is-a-firewall-definition-types-uses\/\">firewalls<\/a> \u2013 the client still has a secure connection with the SSL terminator, which is acting as a pass-through.<\/p>\n<p><strong>Here\u2019s a visualization of SSL Termination:<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-7769\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/SSL-Termination.jpg\" alt=\"How SSL offloading Work\" width=\"811\" height=\"281\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/SSL-Termination.jpg 811w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/SSL-Termination-300x104.jpg 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/SSL-Termination-768x266.jpg 768w\" sizes=\"auto, (max-width: 811px) 100vw, 811px\" \/><\/p>\n<p>SSL Bridging is extremely similar conceptually, except rather than sending the traffic and requests on via HTTP, it re-encrypts everything before sending it to the application server.<\/p>\n<p><strong>Here&#8217;s a visualization of SSL Bridging:<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-7768\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/SSL-Bridging.jpg\" alt=\"SSL Bridging\" width=\"811\" height=\"277\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/SSL-Bridging.jpg 811w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/SSL-Bridging-300x102.jpg 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/SSL-Bridging-768x262.jpg 768w\" sizes=\"auto, (max-width: 811px) 100vw, 811px\" \/><\/p>\n<p>Both allow you to perform traffic inspection and can help tremendously when you\u2019re dealing with high volumes of traffic on larger networks.<\/p>\n<p>Bear in mind, encryption is an incredibly CPU-intensive task. When the industry migrated from 1024-bit RSA keys to 2048-bit ones, the CPU-usage involved increased somewhere between 4-7 times depending on server. We\u2019ll likely never even get to 4096-bit keys because frankly, at that point the increase in cpu-usage isn\u2019t consummate to the improvement in security. That\u2019s why we\u2019re seeing a push towards more <a href=\"https:\/\/www.thesslstore.com\/blog\/understanding-ecc-5-minutes\/\">elliptic curve-based cryptosystems<\/a>.<\/p>\n<p>So let\u2019s cover one last item: should you consider SSL offloading?<\/p>\n<p>And frankly, that all comes down to you, your website and what you\u2019re trying to do. A large media site like an ESPN or a CNN would be well-suited to use a load balancer owing to the volume of traffic they both handle. On the other hand, if you\u2019re just running a website for a local bakery, you\u2019d probably be fine just letting your server handle everything\u2014especially with the <a href=\"https:\/\/www.thesslstore.com\/blog\/tls-1-3-everything-possibly-needed-know\/\">improvements made by TLS 1.3<\/a>.<\/p>\n<p>That\u2019s all for today,<em> as always, leave any comments or questions below.<\/em><\/p>\n<span style=\"--tl-form-height-m:861.156px;--tl-form-height-t:899.625px;--tl-form-height-d:899.625px;\" class=\"tl-placeholder-f-type-shortcode_12653 tl-preload-form\"><span><\/span><\/span>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-7276\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568.jpg\" alt=\"Hashed Out by The SSL Store is the voice of record in the SSL\/TLS industry.\" width=\"1559\" height=\"407\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568.jpg 1559w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-300x78.jpg 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-768x200.jpg 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/08\/bigstock-222348568-1024x267.jpg 1024w\" sizes=\"auto, (max-width: 1559px) 100vw, 1559px\" \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>What is SSL Offloading? Performing SSL at the Load Balancer level. Today we\u2019re going to cover a question that comes up from time to time, and may seem especially foreign&#8230;<\/p>\n","protected":false},"author":6,"featured_media":7765,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[130],"tags":[],"class_list":["post-7763","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-everything-encryption","post-without-tags"],"views":83298,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/10\/bigstock-Dark-Server-Room-Data-Center-S-251384020_edited.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/7763","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=7763"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/7763\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/7765"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=7763"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=7763"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=7763"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}