Chapter 19. Configuring the Certificate System for High Availability
418
Figure 19.1. Certificate System Example
As this diagram indicates, only one of the CAs can generate the CRLs. See
Section 19.4, “Clone-
Master Conversion”
for more information about configuring a clone for CRL generation during cloning.
19.1.2. Load Balancing
The load balancer in front of a Certificate System system is what provides the actual failover support
in a high availability system. A load balancer can also provide the following advantages as part of a
Certificate System system:
• DNS round-robin, a feature for managing network congestion that distributes load across several
different servers.
• Sticky SSL, which makes it possible for a user returning to the system to be routed the same host
used previously.
Consult the documentation for the load balancer for more information about the features, advantages,
and configuration of a load balancer.
19.2. Cloning Preparation
Cloning a subsystem creates two server processes performing the same functions: another, new
instance of the subsystem is created and configured to use the same keys and certificates to perform
Содержание CERTIFICATE SYSTEM 7.2 - MIGRATION GUIDE
Страница 36: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Страница 144: ...124 ...
Страница 160: ...140 ...
Страница 208: ...188 ...
Страница 210: ...190 ...
Страница 256: ...236 ...
Страница 282: ...Chapter 12 Certificate Profiles 262 Parameter IssuerName_n IssuerType_n ...
Страница 285: ...Freshest CRL Extension Default 265 Parameter PointName_n PointIssuerName_n ...
Страница 335: ...Configuring Mappers 315 Figure 14 9 Selecting a New Mapper Type 6 Edit the mapper instance and click OK ...
Страница 362: ...342 ...
Страница 376: ...356 ...
Страница 436: ...416 ...
Страница 490: ...470 ...
Страница 504: ...484 ...