For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

mpete32_168869's avatar
Oct 15, 2015

Load balancing Microsoft Certificate Server invironment

I have an internal ADCS environment with a offline root CA, 2 Enterprise Intermediate CA's and (soon to be) 2 OCSP responders. I would like to design an configuration where certificate requests are load balanced between the two Intermediate CA's and OCSP responses are load balanced between the two OCSP responders. Have found very little info regarding design examples or suggestions regarding this. Has anyone had any experience in setting this up?

 

Much Thanks ! Mark

 

2 Replies

  • Hi,

     

    I strongly not recommend to configure load balancing to manage certificate lifecycle. Are you configuring ADCS clustering or do you have only 2 different Intermediate CA. Are you using SCEP ?

     

    But, if you really need to loadbalance your CAs, you can create a "Performance L4" VS, assign a pool containing both CA members and add source address persistence to your VS.

     

    Depending on the certificate delivery workflow, you will not be able to guarantee that the user come to the same CA during the whole enrollment process.

     

    You can load balance OCSP request to ocsp responders and of course CRL distribution points to (recommended for security reason) an external website (can be ocsp responders)