Re: SSL Certificates on NLB Cluster:: Exporting Single Key vs. Unique

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Buy a multi-server cert.

Cheers,

Rodney R. Fournier

MVP - Windows Server - Clustering
http://www.nw-america.com - Clustering Website
http://www.msmvps.com/clustering - Blog
http://www.clusterhelp.com - Cluster Training
ClusterHelp.com is a Microsoft Certified Gold Partner


"Jay" <Jay@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:90A584EE-94DD-419B-95D8-ABD25ECDF831@xxxxxxxxxxxxxxxx
What are the advantages/disadvantages of Exporting a Single Certificate to
all servers on the NLB Cluster vs. installing a unique certificate on each
server?

I can think of few but will like the leading experts to add/modify.

Exporting a Single Certificate
i) ADVANTAGE:: Ease of deployment. Can Use Imaging to deploy same image on
the similar hardware cluster.
ii) DISADVANTAGE:: If key gets compromised, all servers become vulnerable.

Unique Certificate
i) ADVANTAGE:: Each server has its own key, one key getting compromized
keeps the other servers safe.
ii) DISADVANTAGE:: Can't deploy the same image to all servers on the
cluster.

There must be a lot more that I don't know about. Any help or
modifications
are more than welcome.

Thanks.


.



Relevant Pages

  • Re: Windows 2003 Network Load Balancing Problem
    ... Sadly my servers websites were configured with specific IPs and host ... I find it very strange why the NLB driver can receive on a virtual IP ... he set his IIS website to use ALL UNASSIGNED addresses rather than ... specifically pointing it at the single virtual cluster address. ...
    (microsoft.public.windows.server.clustering)
  • Re: upgrading sql2k cluster to sql2005
    ... that databases get locked off in the current cluster and then properly ... I maintain many SQL servers as ... Who is going to track down all of the applications that need to have ...
    (microsoft.public.sqlserver.clustering)
  • Re: Load Balanced TS Servers and Unicast Flooding
    ... Remove each on of your tse servers from the cluster, ... Start adding them back to the NLB Cluster. ... > NICs. ...
    (microsoft.public.windows.terminal_services)
  • Re: question regarding NTP configuration for clusters, and "cluster time" stability
    ... cluster ranging in size from 4 to over 100 nodes. ... external NTP servers nor any hardware based time sources. ... NTP server or servers, those nodes with external connections were ... to have each node peer with a small number of other nodes (four each ...
    (comp.protocols.time.ntp)
  • Re: High Availability FreeBSD www cluster
    ... So I am a bit lost and i am wanting to learn how to cluster freebsd ... A means to detect failed / out of service machines and redirect traffic to alternative servers ... or you have to store the session state in a way ...
    (freebsd-questions)