CA-HSM clustering


hi

i understand there lots of threads talking ca clustering, have specific requirement , not able find answer. apologies if feel there answers around.

my set is:

site - ca1 configured hsm1.

site b - ca2 configured hsm2

the cluster made of ca1 & ca2. certificate data base shared ca1 & ca2.

do need include hsm1 & hsm2 in cluster well? planning not cluster hsms avoid ca applications accessing hsm across sites.

my understanding is:

when ca1 goes down, ca2 become active node , should start using hsm2.

when hsm1 down, ca1 still active node. when ca1 tries contact hsm1 fail , ca2 becomes active node , starts using hsm2.

please rectify understanding incorrect.

thanks

sanurajan.

> need include hsm1 & hsm2 in cluster well?

no, don't need. hsms must attached respective cluster nodes only. ca should not have access hsm2 , ca access hsm1.


my weblog: http://en-us.sysadmins.lv
powershell pki module: http://pspki.codeplex.com
windows pki reference: on technet wiki



Windows Server  >  Security



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS