Rail Users Ireland Forum

Go Back   Rail Users Ireland Forum > General Information & Discussion > Rail Users Ireland Canteen
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread Display Modes
Prev Previous Post   Next Post Next
Old 28-04-2010, 16:58   #13
robdrysdale
Member
 
Join Date: Dec 2005
Posts: 75
Default

Quote:
Originally Posted by markpb View Post
It's not hard to terminate the SSL connection on one machine and then direct one URL to the IIS server and another to the Apache server. It's fully acceptable to do that under PCI-DSS rules. There's no reason for Irish Rail to adopt the approach they've taken other than laziness.
Yep. It's called ProxyPass on Apache and I believe Application Request Routing on IIS (which I believe they are running on their main irishrail.ie server). See http://www.iis.net/download/ApplicationRequestRouting Pretty trivial to do. Use it all the time on servers in work.

Running on port 8443 is pretty bad IT really.

Also from a security perspective don't think I'd ever expose an Apache Tomcat directly server to the external world as they have done. I'd question whether their infrastructure can handle the load of many thousands of users as this system goes live.
robdrysdale is offline   Reply With Quote
 


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT. The time now is 15:47.


Powered by vBulletin
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.