Day 20: Navigating the SSL/TLS Seas π’π

π Hello! I'm passionate about DevOps and have over 1+ years of experience in the field. I'm proficient in a variety of cutting-edge technologies and always motivated to expand my knowledge and skills. Let's connect and grow together!
SKILLS:
πΉ Languages & Runtimes: Python, Shell Scripting, HCL, YAML πΉ Cloud Technologies: AWS, Microsoft Azure, GCP πΉ Infrastructure Tools: Docker, Terraform, AWS CloudFormation πΉ Other Tools: Linux, Git and GitHub Actions, Jenkins, Jira, GitLab (beginner), Docker, AWS DevOps πΉ Web Development: HTML, CSS, Bootstrap, Python, SQL
Job & Responsibilities:
π Improved development efficiency by implementing CI/CD pipelines, resulting in a 30% reduction in deployment time on the test server. π Strengthened deployment and testing reliability by utilizing Docker containers and optimizing Dockerfile, reducing development issues on the test server by 20%. βοΈ Automated S3 bucket log creation with Shell scripting, eliminating 100% of manual search and saving 2 hours per week. π Scheduled EC2 instance start/stop using Lambda functions and Event Bridge, leading to a 25% decrease in infrastructure costs. π§ Utilized AWS, Linux, Python, Docker, Shell scripting, Terraform, Jenkins Pipelines, and automation to streamline workflows and improve overall system performance.
I'm very detail-oriented and possess strong written and verbal communication skills. As a high performer with a possibility mindset, I strive to solve problems using efficient approaches.
Let's Connect & Grow:
If you find my profile suitable for the role you are searching for, please feel free to reach out to me at sumanprasad9766@gmail.com.
Introduction π
Embark on a journey into the realm of SSL/TLS, where encryption transforms the waves of data into secure passages. Let's unravel the basics of SSL/TLS certificates, their orchestration within Load Balancers, and the art of safeguarding connections. Get ready to set sail into the world of secure communication!
SSL/TLS - A Secure Prelude ππ
What's in a Name?
SSL, or Secure Sockets Layer, and its successor TLS, Transport Layer Security, are cryptographic protocols orchestrating secure connections. Though TLS is the modern star, the term SSL is still affectionately used. Public SSL certificates, issued by Certificate Authorities like Comodo and Let's Encrypt, play a pivotal role, ensuring encrypted journeys across the web.
Certificate Lifelines β³π
SSL certificates have a life cycle marked by expiration dates. Certificate renewal is a dance of security, ensuring your encryption remains a shield against prying eyes.
Load Balancer - SSL Symphony πΆπ
Certificate Management
In the Load Balancer orchestra, an X.509 certificate takes center stage, managing SSL/TLS connections. AWS Certificate Manager (ACM) is the conductor, allowing seamless certificate management. You can also upload your certificates, orchestrating a symphony of secure connections.
HTTPS Listener Choreography
In the HTTPS listener ballet, a default certificate takes the lead. Supporting multiple domains is an art form, accomplished with optional certificate lists. Clients gracefully use Server Name Indication (SNI) to specify their destination hostname, creating a harmonious connection.
SSL β Server Name Indication (SNI) ππ
Artistry in Handshakes
SNI shines in the art of handling multiple SSL certificates on one server. A newer protocol requiring clients to reveal the target server hostname during the initial SSL handshake, SNI enables servers to gracefully pick the correct certificate. Note: Works wonders for ALB & NLB but takes a bow for CLB.
Elastic Load Balancers - SSL Ensembles ππ
The Classic Symphony (CLB)
Classic Load Balancers play a singular tune, supporting only one SSL certificate. Multiple CLBs twirl in unison for varied SSL certificates across hostnames.
The ALB & NLB Harmony (v2)
Application Load Balancers and Network Load Balancers, the newer virtuosos, support multiple SSL certificates. They dance to the SNI melody, creating a symphony of secure connections across multiple domains.
Connection Draining - A Safe Exit ππ§
A Graceful Finale
Connection Draining (CLB) and Deregistration Delay (ALB & NLB) take a bow as the curtain falls. They ensure in-flight requests complete their performance before instances gracefully exit or go under maintenance. This graceful ballet prevents abrupt interruptions and adds finesse to your Load Balancer orchestration.
Conclusion π
As we navigate the SSL/TLS seas, may your connections be secure, your certificates ever-renewing, and your Load Balancer orchestra playing a symphony of encrypted harmony. Sail on, brave mariner, into the secure waters of SSL/TLS! ππ’




