First, we are big fans of Linode. We have been testing the API and all the goodies that Linode provide for awhile in the hope that we can migrate a mid-size client with PCI DSS compliance requirements on Linode from bare-metal LAMP stack hardware we host in the same data center as they do.
So we finally set up a NodeBalancer to terminate SSL for our web nodes and pointed a PCI scan from Trustwave.
We passed all their vectors except for one that we have no control over!
The scan shows that the TLS v1.0 protocol is supported by the NodeBalancer.
Has anyone here overcome this?
The only choice we have is to remove the nodebalancer and terminate SSL at the host level. This would mean that the awesome autoscaling code that we have been writing to bring nodes up and down behind the nodebalancer will be completely wasted.

We need a central load balancer to do the SSL stuff so that nodes can be added/removed as needed.
Of course, we can build our own load balancer using squid or nginx but the key benefit of a cloud provider is the ready-made tools and API. So I am very disappointed to face this issue.
Anyone else faced this issue?
_________________
Custom Web Software Development & Cloud Management Services
Company:
http://evoknow.comBooks:
http://www.amazon.com/Mohammed-J.-Kabir/e/B001IYX5ZY