mark75081

Absent Member.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
2015-03-09
17:42
875 views
Certificate Authority CA Role question
Well I haven't asked a question on here in quite some time.
Does anyone know if I can export my CA role and cert from first primary servwer ZEN internal CA store and import on another primary for redundant internal zen CA servers?
Not sure if this is supported or even works in case one bites the dust.
Thanks in advance 🙂
Does anyone know if I can export my CA role and cert from first primary servwer ZEN internal CA store and import on another primary for redundant internal zen CA servers?
Not sure if this is supported or even works in case one bites the dust.
Thanks in advance 🙂
3 Replies
CRAIGDWILSON

Micro Focus Expert
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
2015-03-09
19:22
mark7508;2349159 wrote:
Well I haven't asked a question on here in quite some time.
Does anyone know if I can export my CA role and cert from first primary servwer ZEN internal CA store and import on another primary for redundant internal zen CA servers?
Not sure if this is supported or even works in case one bites the dust.
Thanks in advance 🙂
No, you can't have "redundant".
But the CA server is only needed when Generating Certs such as when building a new Primary or configuring an Auth Satellite.
I've seen folks lose their CA server and not know it for a year or more :))
Simply make sure you have followed the steps for backup up your CA and if you ever lose your CA server permanently, you can use those files to install the CA service on another server.
--
Please give a hearty thumbs up to any post you find helpful!
To find articles by Craig Wilson simply follow the link: Craig Wilson's Tips!
Please give a hearty thumbs up to any post you find helpful!
To find articles by Craig Wilson simply follow the link: Craig Wilson's Tips!
mark75081

Absent Member.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
2015-03-09
19:50
CRAIGDWILSON;2349164 wrote:
No, you can't have "redundant".
But the CA server is only needed when Generating Certs such as when building a new Primary or configuring an Auth Satellite.
I've seen folks lose their CA server and not know it for a year or more :))
Simply make sure you have followed the steps for backup up your CA and if you ever lose your CA server permanently, you can use those files to install the CA service on another server.
Thanks I was mainly asking since I was replacing the main Primary with one of our others. But already got it going. Thanks for the reply
CRAIGDWILSON

Micro Focus Expert
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
2015-03-10
11:50
mark7508;2349167 wrote:
Thanks I was mainly asking since I was replacing the main Primary with one of our others. But already got it going. Thanks for the reply
When moving the CA, keep in mind that all certs will still say they were issued by the original server.
As Bizzarre as that may seem, it is normal and make no attempt to fix this.
The reason is that the "CA" was created with a "Name" that just happened to match the server's name.
So the issuer is not the ServerOS Name nor the ZCM Object's name but the Name of the CA which all happen to match initially.
When you move the "CA" to a new server, the CA's name cannot change w/o breaking stuff.
Just giving this warning because folks are always trying to "Fix" this and getting themselves in trouble.
--
Please give a hearty thumbs up to any post you find helpful!
To find articles by Craig Wilson simply follow the link: Craig Wilson's Tips!
Please give a hearty thumbs up to any post you find helpful!
To find articles by Craig Wilson simply follow the link: Craig Wilson's Tips!