
Chapter 19. Configuring the Certificate System for High Availability
418
Figure 19.1. Certificate System Example
As this diagram indicates, only one of the CAs can generate the CRLs. See
Section 19.4, “Clone-
Master Conversion”
for more information about configuring a clone for CRL generation during cloning.
19.1.2. Load Balancing
The load balancer in front of a Certificate System system is what provides the actual failover support
in a high availability system. A load balancer can also provide the following advantages as part of a
Certificate System system:
• DNS round-robin, a feature for managing network congestion that distributes load across several
different servers.
• Sticky SSL, which makes it possible for a user returning to the system to be routed the same host
used previously.
Consult the documentation for the load balancer for more information about the features, advantages,
and configuration of a load balancer.
19.2. Cloning Preparation
Cloning a subsystem creates two server processes performing the same functions: another, new
instance of the subsystem is created and configured to use the same keys and certificates to perform
Summary of Contents for CERTIFICATE SYSTEM 7.2 - MIGRATION GUIDE
Page 36: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Page 144: ...124 ...
Page 160: ...140 ...
Page 208: ...188 ...
Page 210: ...190 ...
Page 256: ...236 ...
Page 282: ...Chapter 12 Certificate Profiles 262 Parameter IssuerName_n IssuerType_n ...
Page 285: ...Freshest CRL Extension Default 265 Parameter PointName_n PointIssuerName_n ...
Page 362: ...342 ...
Page 376: ...356 ...
Page 436: ...416 ...
Page 490: ...470 ...
Page 504: ...484 ...