Ssl – HAProxy and Stunnel PCI Compliance

haproxyload balancingpci-dsssslstunnel

I am setting up HAProxy to load balance between two web servers. Some of the pages on the site require SSL. Stunnel is handling the https connections and passing them off to haproxy (Stunnel contains the cert). HAProxy will hand off requests to the web servers using http. Will containing the web servers and haproxy in an internal network be enough to be PCI compliant? Is there anything I need to watch out for?

Best Answer

4.1 Use strong cryptography and security protocols (for example, SSL/TLS, IPSEC, SSH, etc.) to safeguard sensitive cardholder data during transmission over open, public networks.

Yes, your architecture is appropriate to the standard.

https://www.pcisecuritystandards.org/documents/pci_dss_v2.pdf