How Does QuotaGuard Handle Proxying HTTPS connections?
Table of contents
We always get a few questions regarding how QuotaGuard handles proxying HTTPS connections.
How does QuotaGuard handle proxying HTTPS connections?
Is it accurate that Quotaguard Static has HTTPS connections to Heroku?
If not, that would mean our traffic would be unencrypted between QuotaGuard’s servers and Heroku?
This is one of the main reasons we created QuotaGuard Shield, to assist with this type of security request and solution.
The answer depends on the direction of the traffic.
Outbound HTTPS (requests from your app to external APIs): QuotaGuard Static and QuotaGuard Shield both carry outbound HTTPS through a blind CONNECT tunnel. Neither product decrypts your payload, and no certificates need to be loaded. The difference is the hop between your app and the proxy: on Static that hop uses the plain HTTP proxy protocol, while Shield encrypts it with TLS. Use Shield for regulated data such as HIPAA or PCI workloads.
Inbound HTTPS (traffic arriving at your app through QuotaGuard): there are two options:
-
Customers can choose to use QuotaGuard Shield, where inbound TLS passes straight through to your app (SNI passthrough) and you control your own certificates for maximum security.
-
Customers can use QuotaGuard Static and have their SSL certificates loaded into our proxy servers so that inbound TLS terminates at the proxy and QuotaGuard can support HTTPS for you.
Adding certificates for QuotaGuard Static is easily configurable in the QuotaGuard dashboard.
However, we strongly recommend not sharing your certificates with third-parties (like QuotaGuard) and using QuotaGuard Shield to retain physical possession of your certificates at all times.