CA-HSM clustering
hi
i understand there lots of threads talking ca clustering, have specific requirement , not able find answer. apologies if feel there answers around.
my set is:
site - ca1 configured hsm1.
site b - ca2 configured hsm2
the cluster made of ca1 & ca2. certificate data base shared ca1 & ca2.
do need include hsm1 & hsm2 in cluster well? planning not cluster hsms avoid ca applications accessing hsm across sites.
my understanding is:
when ca1 goes down, ca2 become active node , should start using hsm2.
when hsm1 down, ca1 still active node. when ca1 tries contact hsm1 fail , ca2 becomes active node , starts using hsm2.
please rectify understanding incorrect.
thanks
sanurajan.
> need include hsm1 & hsm2 in cluster well?
no, don't need. hsms must attached respective cluster nodes only. ca should not have access hsm2 , ca access hsm1.
my weblog: http://en-us.sysadmins.lv
powershell pki module: http://pspki.codeplex.com
windows pki reference: on technet wiki
Windows Server > Security
Comments
Post a Comment