I'm using Cherokee in amazon loadbalancer serving to 3 cherokee instances for now, but there's a problem with ip origin check. Amazon documentation says that you can't use loadbalancer ip cause it can change over time, while cherokee "Don't check origin" warns about not using a list of ip addresses to limit the possible security hole.
I can't use loadbalancer ip, but i can't leave x-Forwarded-For without any content, is there a huge security issue or i'm being paranoic?
_______________________________________________ Cherokee mailing list [email protected] http://lists.octality.com/listinfo/cherokee
