Re: Certificate Authority (CA) Failover - Possible?



In article <D2149F7A-235A-432D-AB33-80BAC18B15BD@xxxxxxxxxxxxx>,
Frank@xxxxxxxxxxxxxxxxxxxxxxxxx says...
I hope this is the correct board to ask this question... I am trying to setup
a CA for our company, not for AD purposes, but for client side web
certificates that can be issued to our customers to browse our website. Now
with the question...

Is there a way to setup 2 servers as the CA for failover purposes? I'm
thinking kind of like how DNS servers work. Where if one goes down, the other
one will just take over. It will be very important for the CA to stay up
because of the constant changes we will be making in the Issuing and denying
of certificates. Any information or suggestions would be great. Thanks!

-Frank

You can accomplish some of what you want.
- You can have a DNS CNAME record that would send you to either of the
two CAs.
- Certificates would be fine as both CAs would chain to a common root CA
(you would need a two tiered hierarchy with an offline root CA)
- You would be able to issue any number of certificates from either CA
- The CA that issued the certificate would have to be up though to
revoke a certificate.

Today, there is no way to cluster the CA so that failover could happen.
What I have described is about all that you can do.

brian
.



Relevant Pages

  • Re: Problem with AT_SIGNATURE in CryptGetUserKey
    ... As you said, my cert has the purposes you told me, but I have other key/certificate pair of other CA with exactly the same purposes, and I can read it without AT_SIGNATURE. ... When I load my private key at startup my programs doesn´t know if it will be used for signing or authentication, and I suppose nothing in the certificate sets how it must be read from CSP. ... >> For the certificates that you claim are similar, ...
    (microsoft.public.platformsdk.security)
  • Re: Mild Rant at GRO
    ... dealing with the requests for certificates for family history ... purposes. ...
    (soc.genealogy.britain)
  • Re: Ernest Chadwick
    ... > other purposes)? ... Jean doesn't buy certificates. ... Prev by Date: ...
    (soc.genealogy.britain)
  • Certificates
    ... My last cert. ... Certificates are getting to a bit confusing. ... many types used for many different purposes. ...
    (microsoft.public.cert.exam.mcse)
  • Re: autoenrolment/certificate questions
    ... If we now create our own version 2 template "workstation ... Supersedeing is the recomended way of doing this, the old certificates will ... CAs is to just configure them to issue the same templates and have the same ... > are appearing in the local cert store of all the clients. ...
    (microsoft.public.windows.server.security)