3.7.1. Cloning a Subsystem

3.7.1. Cloning a Subsystem

For failover protection and for availability for high-traffic subsystems, it is possible to clone an existing CA, DRM, TKS, or OCSP subsystem. To clone a subsystem, do the following:

  1. Create a new instance using pkicreate.

  2. Open the configuration wizard.

  3. In the Security Domain panel, add the clone to the same security domain to which the master belongs.

  4. The Subsystem Type panel sets whether to create a new instance or a clone; select the clone radio button.

    Selecting the Subsystem to Clone
    Figure 3.16. Selecting the Subsystem to Clone

  5. Give the path and filename of the PKCS #12 backup file which was saved when the master instance was created. If a backup was not created at that time, use the pk12util utility to create a PKCS #12 file.

    Supplying the Key and Certificate Information
    Figure 3.17. Supplying the Key and Certificate Information

    Note

    When cloning a CA, the master and clone instances have the same CA signing key.

  6. The subsystem information is automatically supplied from the master instance to the clone instance once the keys are successfully restored. Complete the configuration process.

  7. Restart the clone instance.

    /etc/init.d/instance-id restart
    

For more information on using cloning as part of a deployment strategy, see Chapter 21, Configuring the Certificate System for High Availability.