CA-HSM clustering


hi

i understand there lots of threads talking ca clustering, have specific requirement , not able find answer. apologies if feel there answers around.

my set is:

site - ca1 configured hsm1.

site b - ca2 configured hsm2

the cluster made of ca1 & ca2. certificate data base shared ca1 & ca2.

do need include hsm1 & hsm2 in cluster well? planning not cluster hsms avoid ca applications accessing hsm across sites.

my understanding is:

when ca1 goes down, ca2 become active node , should start using hsm2.

when hsm1 down, ca1 still active node. when ca1 tries contact hsm1 fail , ca2 becomes active node , starts using hsm2.

please rectify understanding incorrect.

thanks

sanurajan.

> need include hsm1 & hsm2 in cluster well?

no, don't need. hsms must attached respective cluster nodes only. ca should not have access hsm2 , ca access hsm1.


my weblog: http://en-us.sysadmins.lv
powershell pki module: http://pspki.codeplex.com
windows pki reference: on technet wiki



Windows Server  >  Security



Comments

Popular posts from this blog

Azure MFA with Azure AD and RDS

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com