What is SSL Termination? Definition & Related FAQs | Avi Networks (2024)

<< Back to Technical Glossary

SSL Termination Definition

SSL termination describes the transition process when data traffic becomes encrypted and unencrypted. This happens at the server end of a secure socket layer (SSL) connection.

What is SSL Termination? Definition & Related FAQs | Avi Networks (1)

FAQs

What Is SSL Termination?

SSL termination is a process by which SSL-encrypted data traffic is decrypted (or offloaded). Servers with a secure socket layer (SSL) connection can simultaneously handle many connections or sessions. An SSL connection sends encrypted data between an end-user’s computer and web server by using a certificate for authentication. SSL termination helps speed the decryption process and reduces the processing burden on backend servers.

How Does SSL Termination Work?

SSL termination intercepts encrypted https traffic when a server receives data from a secure socket layer (SSL) connection in an SSL session. SSL termination or SSL offloading decrypts and verifies data on the load balancer instead of the application server. Spared of having to organize incoming connections, the server can prioritize on other tasks like loading web pages. This helps increase server speed. SSL termination represents the end — or termination point — of an SSL connection.

What is SSL Termination Load Balancer?

SSL termination at load balancer is desired because decryption is resource and CPU intensive. Putting the decryption burden on the load balancer enables the server to spend processing power on application tasks, which helps improve performance. It also simplifies the management of SSL certificates.

Is SSL Termination Secure?

Secure socket layer (SSL) connections are important for sensitive data. One point to note is that after SSL termination unencrypted traffic is sent between the load balancer and the backend server on the local area network. However, for security purposes, administrators can choose to re-encrypt the traffic at the load balancer before sending it to the servers.

SSL termination at load balancer alleviates web servers of the extra compute cycles needed to decrypt SSL traffic. The security risk of terminating at the load balancer is lessened when the load balancer is within the same data center as the web servers. Some load balancers also provide the ability to use a self-signed SSL between the load balancer and web servers. This provides a secure connection, but requires more compute power.

Can SSL Termination be Performed in Software?

With the advancement of Intel x86-based CPU technology, support for SSL on standard Intel hardware has increased dramatically. The use of Elliptic Curve Cryptography (ECC) keys with shorter key lengths than traditional RSA 2K keys for SSL encryption has put software based load balancers on x86 servers ahead in many cases.

An Advanced Encryption Standard New Instructions (AES-NI) is now integrated into many processors. The purpose of the instruction set is to improve the speed, as well as the resistance to side-channel attacks, of applications performing encryption and decryption the latest security standards. Another key reason to use software-based SSL termination is to completely decouple the dependence on hardware to a simple software version upgrade, and to get support for the latest security versions and bug fixes.

Does Avi Offer SSL Termination?

Using 100% software Avi as the endpoint for SSL enables it to deliver high performance in terms of SSL transactions per second (TPS), maintain full visibility into the traffic and also to apply advanced traffic steering, application security via WAF and acceleration features. Avi offers support for both RSA 2K as well as modern ECC keys for SSL. With the ability to scale a single virtual service horizontally (across multiple servers) as well as scale vertically on a single server (with more cores and higher processing power), Avi’s elastic load balancers support millions of SSL transactions per second and better scalability and price/performance benefits than hardware load balancers.

For more on the actual implementation of load balancing, security applications and web application firewalls check out ourApplication Delivery How-To Videos.

For more information on SSL termination see the following resources:

Featured Resources

Videos

SSL/TLS with PFS for OpenStack Apps

Learn how to implement high performance SSL/TLS with PFS in OpenStack with real-time autoscaling.

Videos

SSL/TLS with PFS for OpenStack Apps

Solution Brief

Avi for Security: SSL Everywhere

Learn how Avi delivers enterprise-grade web apps with SSL/TLS encryption.

View Now

Solution Brief

Avi for Security: SSL Everywhere

White Papers

IDC Study: The Business Value of VMware NSX Advanced Load Balancer

IDC interviewed organizations using the VMware NSX Advanced Load Balancer to deploy application services .

View Now

White Papers

IDC Study: The Business Value of VMware NSX Advanced Load Balancer

What is SSL Termination? Definition & Related FAQs | Avi Networks (2024)

FAQs

What is SSL Termination? Definition & Related FAQs | Avi Networks? ›

This process of decrypting traffic before passing it on is called SSL termination. Obviously, this means that the traffic between the web server and load balancer is no longer encrypted, increasing the risk of an attack, but keeping the load balancer in the same location reduces that risk.

What does SSL termination mean? ›

SSL termination is a process by which SSL-encrypted data traffic is decrypted (or offloaded). Servers with a secure socket layer (SSL) connection can simultaneously handle many connections or sessions.

What is the meaning of SSL in networking? ›

SSL: Secure Sockets Layer

SSL is standard technology for securing an internet connection by encrypting data sent between a website and a browser (or between two servers).

What is the difference between SSL pass through and SSL termination? ›

SSL offloading (aka SSL termination): The Load Balancer decrypts incoming HTTPS traffic, and sends it to the backend server unencrypted. SSL passthrough: The Load Balancer does not decrypt incoming HTTPS traffic, and sends it to the backend server 'as is'.

Where can I do SSL termination? ›

SSL termination is the process of decrypting traffic before it's passed on another server such as Access Gateway. When used with a load balancer, SSL can be terminated at the load balancer or encrypted traffic can be passed directly to Access Gateway and SSL terminated there.

What happens if I turn off SSL? ›

Disabling SSL can create a security exposure where a malicious user within the network can attack the system.

How long does an SSL connection last? ›

TLS/SSL certificate validity periods are currently 398 days, or about 13 months.

What are the three phases of SSL? ›

Handshake Protocol
  • First Phase - Establishing Security Capabilities. ADVERTIsem*nT. ...
  • Second Phase - Server Authentication and Key Exchange. ADVERTIsem*nT. ...
  • Third Phase - Client Authentication and Key Exchange. ADVERTIsem*nT.

What happens without SSL? ›

Without SSL, your site visitors and customers are at higher risk of being having their data stolen. Your site security is also at risk without encryption. SSL protects website from phishing scams, data breaches, and many other threats. Ultimately, It builds a secure environment for both visitors and site owners.

Why is terminating SSL at the load balancer level an issue? ›

SSL-terminated load balancers decrypt the traffic at the traffic manager and pass unencrypted traffic to the back-end node. Because of this, the customer's back-end nodes don't know what protocol the client requested.

What is the difference between SSL and TLS? ›

However, SSL is an older technology that contains some security flaws. Transport Layer Security (TLS) is the upgraded version of SSL that fixes existing SSL vulnerabilities. TLS authenticates more efficiently and continues to support encrypted communication channels.

Why do we need TLS termination? ›

In this process, the SSL/TLS encryption is terminated, and the communication between the client and the server/application happens over unencrypted HTTP. SSL termination helps to speed up the decryption process and reduces the processing burden on backend servers.

Who manages my SSL? ›

TLS/SSL certificates are commonly managed by IT personnel and software engineers. However, certificates can theoretically be requested and purchased by any person in your organization needing to secure a website or server, unless you specify authorization policies within your certificate management console.

How do I clear SSL on my Iphone? ›

Follow these steps to delete the SSL certificate on your iPhone or iPad.
  1. Open the Settings application, and then select General.
  2. Select the Profile containing the SSL Certificate that you would like to delete (Pre-installed SSL cannot be removed).
  3. Tap the Delete Profile and enter your device password.

How do I clear my SSL status? ›

Google Chrome
  1. Start the Windows Control Panel.
  2. In the Find a setting text box, type internet options, and then click Internet Options.
  3. Click the Content tab.
  4. In the Certificates section, click Clear SSL state, and then click OK.

What is meant by SSL offloading? ›

SSL offloading is the process of removing the SSL-based encryption from incoming traffic to relieve a web server of the processing burden of decrypting and/or encrypting traffic sent via SSL. The processing is offloaded to a separate device designed specifically for SSL acceleration or SSL termination.

What does it mean to disable SSL? ›

If you disable SSL that means your website is lacking in security. Google Chrome and other browsers send a signal to the user that this website is not secured.

Top Articles
How to Get Preapproved for a Mortgage - NerdWallet
Psychology of Wordle: Why are people addicted to this viral word game?
No Hard Feelings (2023) Tickets & Showtimes
Libiyi Sawsharpener
Missed Connections Inland Empire
Big Spring Skip The Games
Northern Whooping Crane Festival highlights conservation and collaboration in Fort Smith, N.W.T. | CBC News
How Far Is Chattanooga From Here
Decaying Brackenhide Blanket
biBERK Business Insurance Provides Essential Insights on Liquor Store Risk Management and Insurance Considerations
Premier Boating Center Conroe
Call Follower Osrs
Miss America Voy Forum
Oc Craiglsit
Saberhealth Time Track
Nyuonsite
Nene25 Sports
Buy PoE 2 Chaos Orbs - Cheap Orbs For Sale | Epiccarry
Check From Po Box 1111 Charlotte Nc 28201
8664751911
Florida History: Jacksonville's role in the silent film industry
Nick Pulos Height, Age, Net Worth, Girlfriend, Stunt Actor
Las 12 mejores subastas de carros en Los Ángeles, California - Gossip Vehiculos
Prestige Home Designs By American Furniture Galleries
Ge-Tracker Bond
Tripadvisor Napa Restaurants
Which Sentence is Punctuated Correctly?
Cable Cove Whale Watching
CohhCarnage - Twitch Streamer Profile & Bio - TopTwitchStreamers
Rainfall Map Oklahoma
Craigslist Cars And Trucks Mcallen
What Time Does Walmart Auto Center Open
RUB MASSAGE AUSTIN
Craigslist In Myrtle Beach
Chris Provost Daughter Addie
Craigslist Greencastle
Domino's Delivery Pizza
New Gold Lee
The All-New MyUMobile App - Support | U Mobile
2007 Jaguar XK Low Miles for sale - Palm Desert, CA - craigslist
Nina Flowers
Bill Manser Net Worth
Kb Home The Overlook At Medio Creek
Panolian Batesville Ms Obituaries 2022
Sour OG is a chill recreational strain -- just have healthy snacks nearby (cannabis review)
56X40X25Cm
Plumfund Reviews
Rick And Morty Soap2Day
Great Clips Virginia Center Commons
Wvu Workday
Rise Meadville Reviews
Latest Posts
Article information

Author: Nathanael Baumbach

Last Updated:

Views: 5931

Rating: 4.4 / 5 (75 voted)

Reviews: 90% of readers found this page helpful

Author information

Name: Nathanael Baumbach

Birthday: 1998-12-02

Address: Apt. 829 751 Glover View, West Orlando, IN 22436

Phone: +901025288581

Job: Internal IT Coordinator

Hobby: Gunsmithing, Motor sports, Flying, Skiing, Hooping, Lego building, Ice skating

Introduction: My name is Nathanael Baumbach, I am a fantastic, nice, victorious, brave, healthy, cute, glorious person who loves writing and wants to share my knowledge and understanding with you.