Solved

Steps for implementation of SSL for one domain but on many load balanced servers

Posted on 2004-04-24
3
261 Views
Last Modified: 2010-04-11
I have one website which is load balanced on more than one server. I was told that I only need to pay for one certificate because I have one hostname (or domain) and then I can install them on all other servers.
My questions are:
1- What do I give the CA (Verisign, thawte, etc) so they can sign it and give it back to me
2- How do I install it on all servers
3- What do I need to backup for future installations?
Thanks
0
Comment
Question by:kalmen
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 23

Accepted Solution

by:
Tim Holman earned 500 total points
ID: 10917250
1)  You need to generate a private key and CSR (certificate signing request).  You send this to the CA, then they will send you back the SLL certificate.  

2)  Do you use IIS or Apache ?  With IIS you import an SSL certificate with the Key Manager utility, with Apache, you just dump it into one of the files - http://www.freessl.com/resources/install/freessl/apache_2x.htm

3)  Backup your private key, and the certificate itself.

What load balancers do you use ?  Can you use them to offload SSL ?  Running SSL directly on web servers will slow them down considerably.
0
 
LVL 1

Author Comment

by:kalmen
ID: 10917370
I see, thanks.

So I need to keep the private key and public key as backup? And I can add them to any server that hosts the same domain/hostname.

The load balancers I used have an SSL accelerator installed, so that reduces a lot of load from my servers.

0
 
LVL 23

Expert Comment

by:Tim Holman
ID: 10917449
You should be able to install the SSL cert on just the SSL accelerators themselves, then have the web servers serve up HTTP content which in turn is encrypted by your SSL acceleration device.
In terms of backup, private key AND certificate are required (and a copy of the password !).
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The next five years are sure to bring developments that are just astonishing, and we will continue to try to find the balance between connectivity and security. Here are five major technological developments from the last five years and some predict…
OnPage: Incident management and secure messaging on your smartphone
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…

749 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question