Certificate Authority (CA) - Failover Possible?

Certificate Authority (CA) - Failover Possible?

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Certificate Authority (CA) - Failover Possible? Frank 02-24-2006
Posted by =?Utf-8?B?RnJhbms=?= on February 24, 2006, 8:20 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I hope this is the correct board to ask this question... I am trying to setup
a CA for our company, not for AD purposes, but for client side web
certificates that can be issued to our customers to browse our website. Now
with the question...

Is there a way to setup 2 servers as the CA for failover purposes? I'm
thinking kind of like how DNS servers work. Where if one goes down, the other
one will just take over. It will be very important for the CA to stay up
because of the constant changes we will be making in the Issuing and denying
of certificates. Any information or suggestions would be great. Thanks!

-Frank


Posted by Paul Adare on February 25, 2006, 3:11 am
If you were  Registered and logged in, you could reply and use other advanced thread options
microsoft.public.security news group, =?Utf-8?B?RnJhbms=?=

> Is there a way to setup 2 servers as the CA for failover purposes? I'm
> thinking kind of like how DNS servers work. Where if one goes down, the other
> one will just take over. It will be very important for the CA to stay up
> because of the constant changes we will be making in the Issuing and denying
> of certificates. Any information or suggestions would be great. Thanks!
>

Stand up two CAs and publish the same certificate templates from both of
them. This will allow any client to request a certificate from either
CA.
I'm a little confused as to what exactly you mean by the constant
changes to "issuing and denying" of certificates however, can you
clarify?

--
Paul Adare - MVP Virtual Machines
It all began with Adam. He was the first man to tell a joke--or a lie.
How lucky Adam was. He knew when he said a good thing, nobody had said
it before. Adam was not alone in the Garden of Eden, however, and does
not deserve all the credit; much is due to Eve, the first woman, and
Satan, the first consultant." - Mark Twain

Similar ThreadsPosted
what type of certificate authority? June 16, 2005, 4:08 pm
Certificate Authority type June 16, 2005, 6:01 pm
Problem with certificate authority January 27, 2006, 9:03 am
Microsoft Certificate Authority June 14, 2006, 8:25 am
Problem in Certificate Authority February 23, 2007, 4:09 am
Certificate Authority Settings May 22, 2007, 3:46 pm
Certificate Authority Configuration February 25, 2008, 11:47 pm
Re: Certificate Authority services on W2k forest June 14, 2005, 4:23 pm
Renaming a Certificate Root authority June 28, 2006, 5:16 pm
Local Certificate Authority Server July 7, 2006, 1:53 am

The site map in XML format XML site map

Contact Us | Privacy Policy