03.03.2015 Views

CA eTrust SiteMinder Policy Server Management

CA eTrust SiteMinder Policy Server Management

CA eTrust SiteMinder Policy Server Management

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Key <strong>Management</strong> Scenarios<br />

Key <strong>Management</strong> Scenarios<br />

There are three types of scenarios for key management based on how you<br />

implement <strong>Policy</strong> <strong>Server</strong>s, policy stores and key stores, along with your single<br />

sign-on requirements. These scenarios include:<br />

■<br />

Common <strong>Policy</strong> Store and Key Store<br />

In this scenario, a group of <strong>Policy</strong> <strong>Server</strong>s shares a single policy store and<br />

key store, providing access control and single sign-on in a single cookie<br />

domain.<br />

The policy store data is maintained in a single policy store. Key data is<br />

maintained in a single key store. The key store may be part of the policy<br />

store, or may be a separate store.<br />

Both policy store and key store data may be replicated for failover<br />

purposes. Replication must be configured based on the database or<br />

directory type selected for the policy store. For information about<br />

replication schemes, consult the documentation provided by your database<br />

or directory vendor.<br />

■<br />

Multiple <strong>Policy</strong> Stores with a Common Key Store<br />

In this scenario, groups of <strong>Policy</strong> <strong>Server</strong>s connect to separate policy stores,<br />

but share a common key store, providing access control and single sign-on<br />

across multiple cookie domains.<br />

The policy store data for each group of <strong>Policy</strong> <strong>Server</strong>s is maintained in a<br />

single policy store. Key data for all groups of <strong>Policy</strong> <strong>Server</strong>s is maintained<br />

in a single key store. The separate key store allows Agents associated with<br />

all <strong>Policy</strong> <strong>Server</strong>s to share keys, enabling single sign-on across separate<br />

cookie domains.<br />

Both policy store and key store data may be replicated for failover<br />

purposes. Replication must be configured based on the database or<br />

directory type selected for the policy store. For information about<br />

replication schemes, consult the documentation provided by your database<br />

or directory vendor.<br />

Chapter 6: Configuring and Managing Encryption Keys 51

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!