-
Website
http://www.daemonology.net/blog/ -
Original page
http://www.daemonology.net/blog/2009-09-28-securing-https.html -
Subscribe
All Comments -
Community
-
Top Commenters
-
Marton Trencseni
3 comments · 1 points
-
Ralph Corderoy
4 comments · 1 points
-
da44en
2 comments · 1 points
-
Jason Dusek
2 comments · 1 points
-
royce
9 comments · 1 points
-
-
Popular Threads
-
Supporting FreeBSD
3 weeks ago · 1 comment
-
Supporting FreeBSD
By the way - great post!
What I would like to see instead is a privsep'd Apache (like OpenSSH does it), with sensitive processes separate and locked down by default.
But what we use now is alot like what you already have. We use nginx in one jail, serving static content (images), and providing SSL, but it then passes CGI requests to a FastCGI running in a separate jail. This also makes it easy to load balance, by having more than one fastcgi jail, spread across a number of physical boxes.