EJBCA GUI HA #629
Unanswered
PhilLaCiotat
asked this question in
Q&A
Replies: 1 comment
-
CA key generation is a sensitive process and should generally be performed very controlled. see here: https://docs.keyfactor.com/ejbca/latest/generic-pkcs-11-provider |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Hello Community,
My pb is when having 2 or more ejbca PODs running (under k8s), the GUI can create 2 times the same key in Crypto-token HSM, if access one time to the 1st POD and immediately after tries the creation again (so on 2nd pod due to loadbalancing)
Then in this case 2nd POD is not synchronized with 1st and don't see the just created key... so creating it again is possible (and dramatic !)
My question : how to improve sync between PODs..?
Of course all PODs are accessing the same DB...
Beta Was this translation helpful? Give feedback.
All reactions