CSS with SSL module - how many certs do we need

Hello,
currently moving from server-based certs to CSS/SSL based.
We have two sites, two CSS/SSL on each in ASR mode.
There are two real servers behind each SSL rule for load balancing.
The question becomes how many certificates do we need
for such design ?
For sure we need one per site, then on each site we have Active/Standby CSS's.
Do we need separate certificate for each CSS?
I dont think so, cause only one is active at the time.
I tested it with same certificate on both CSS's on one site, no problem.
The question is will it be ok for production ?
So total number would be 2 cert for such design (one per VIP) if we have one SSL rule per site, and 4 if we have 2 SSL rule per site - is it ok ?
Thank you,
Alex

the certificate is linked to a host name ie: www.mycompany.com.
So, if you have 4 css, all handling traffic for www.mycompany.com, then they can all share the same certificate.
Even if you have the 4 CSS split over 2 sites, using different vip, as long as they handle the same hostname, then they can share the certificate.
Actually, the CSS itself does not care about hostname/certificate mapping.
The CSS will use whatever certificate you configure it to use.
However, browsers make a check url <-> certificate and if there is a mismatch, they pop up an error message.
Regards,
Gilles.

Similar Messages

  • Backend Encryption with SSL module & Self Signed Cert

    I am trying to configure backend encryption using the SSL module to communicate with a server using a self signed certificate. I configured Authenticate verify none. I have not copied any cert info from the server. Do I need to? The SSL module is complaining about an invalid cert. My config is basic.
    service test-service-cf8-be client
    virtual ipaddr 10.6.1.20 protocol tcp port 80
    server ipaddr 10.6.1.22 protocol tcp port 443
    log-auth-failures
    authenticate verify none
    inservice
    Thanks,
    Dave

    Yes it was up and a debug showed an invalid cert message when the service was hit. The answer turned out to be that you still need to import the root CA from the server so that the SSL mod has something to verify the cert against.
    Thanks..

  • How many problems do you need to have with a mac book pro to get it replaced i have had 6 problems and they say they have fixed everything and somthing new happends

    how many problems do you need to have with a mac book pro to get it replaced i have had 6 problems and they say they have fixed everything and somthing new happends
    I have had thehad the:
    ram replaced
    Battery
    Audio
    Trackpad
    os operating system
    fans
    And they still won't replace the laptop for me worst buy ever but i have had a imac for 2 months and nothing at all wrong .

    You could try calling Apple and ask for Customer Relations.
    From Readers Digest-February, 2005
    How to Complain
          You call customer service to complain about a product, and you hang up angrier than when you started. That’s customer rage, a feeling experienced by millions of people with a major complaint, says Scott Broetzmann, president an American firm that tells companies how to offer the best customer service. His secrets to getting good service:
    Have a goal
    If you want your product repaired, say so. Want an apology? Speak up.
    Keep it short
    Focus on one problem, and be succinct.
    Stick with it
    You have to invest the time it takes. Don’t get what you want? Ask for a supervisor.
    Skip ultimatums
    Don’t threaten not to do business with them again. Why should they help you if you won’t buy from them in the future?
    Plead your case
    Many companies have information such as how much money you’ve spent with them and how often you complain. If you’re a good customer, they may be more willing to help.
    Be nice
    You’re unlikely to get what you want if you’re rude.
    Good luck.

  • If I buy CC (with LR CC) how many computers can I install on?

    If I buy CC (with LR CC) how many computers can I install on?

    Hi Droth,
    Its same for all the CC products i.e. you can install any CC app on up to 2 machines.
    ~ Arpit

  • How many cert need for Lync 2013

    How many cert I need to buy???
    [internet] <-->  [TMG]   <--> [Lync edge]
                                                 [Lync front end]
    is it correct to buy this two cert. (then what's the function for)
    Cert 1 for TMG
    Lyncrproxy.abc.com (for
    Reverse Proxy???)
    Meet.abc.com (for web conference)
    Dailin.abc.com (for phone??)
    Lyncweb.abc.com (for ???)
    Lyncdiscover.abc.com (for Mobility client setup)
    Cert 2 for Lync edge
    Sip.abc.com (for SIP Access)
    Lyncwebconf.abc.com (for Web Conferencing Edge service)
    Lyncav.abc.com (for A/V service)
    Thanks 

    You can use one cert across the Edge and Reverse Proxy as follows:-
    sip.abc.com - Lync Access (use as subject name and assign to Edeg Access) (Edge)
    Lyncweb.abc.com - For distribution Group and addressbook service (TMG)
    dialin.abc.com - webconferencing dialin URL (TMG)
    meet.abc.com - Web conferencing meet URL (TMG)
    Lyncwebconf.abc.com - Web Conferencing mnedia (Edge)
    lyncdiscover.abc.com - mobility (Edge)
    The simplest way of requesting this cert is from the Lync Deployment Wizard on the Lync Edge Server. Be sure to marek the request as exportable so the cert can be exported from Edge and imported to TMG.
    Please remember, if you see a post that helped you please click "Vote As Helpful" and if it answered your question, please click "Mark As Answer"
    Lync Sorted blog

  • ISCSI MPIO, how many path do I need to create

    Hi,
    I've a server with 4 NIC connection to a DELL MD32xx which have 8 NIC.
    My question is how many path do I need to create under iSCSI connection.
    Do I need to create a path from each Server NIC to each MD32xx NIC, which will make 32 connection (and doesn't make sense).
    If not, how should I proceed, I've looked at many example and none seem to cover that kind of situation, they just directly connect the server NIC to the MD32xx NIC instead of going through switch for redundancy.
    Thank
    ML

    Hi,
    I've a server with 4 NIC connection to a DELL MD32xx which have 8 NIC.
    My question is how many path do I need to create under iSCSI connection.
    Do I need to create a path from each Server NIC to each MD32xx NIC, which will make 32 connection (and doesn't make sense).
    If not, how should I proceed, I've looked at many example and none seem to cover that kind of situation, they just directly connect the server NIC to the MD32xx NIC instead of going through switch for redundancy.
    Thank
    ML
    Please follow the guides and discussions here:
    Windows MPIO Setup for Dual Controller SAN
    http://social.technet.microsoft.com/Forums/windowsserver/en-US/3fa0942e-7d07-4396-8f2e-31276e3d6564/windows-mpio-setup-for-dual-controller-san?forum=winserverfiles
    It's MD3260 so can be used for 32xx storage unit with iSCSI uplinks.
    StarWind VSAN [Virtual SAN] clusters Hyper-V without SAS, Fibre Channel, SMB 3.0 or iSCSI, uses Ethernet to mirror internally mounted SATA disks between hosts.

  • How many NWDI do I need?

    Hi!
    Our company is an SAP outsourcing unit. We have about 16 landscapes with
    all kinds of SAP products.
    We are going to use NWDI to handle JAVA transport.
    Could you inform us how many NWDI do we need?
    Thanks a lot!

    Hi Jennifer,
    This might help, read
    http://help.sap.com/saphelp_erp2005/helpdata/en/42/f1a03611d83ee4e10000000a1553f7/frameset.htm
    http://help.sap.com/saphelp_nw2004s/helpdata/en/54/347a2a840246b1bbd8fc9154be6658/frameset.htm
    Regards
    Juan
    Please reward with points if helpful

  • How many cals do i need?

    Let say i have 300 active directory accounts but only 100 physical users (with heartbeats), how many CALs do i need per user CAl licensing? Also, if i have 300 emails  accounts in exchange 2010 but only 100 physical users, how many exchange CALS do
    i need? And if 5 users leave the company, does the CALS be free up for the next employees?
    Based on my research, i need 100 AD CALS and 100 exchange CALs but i getting conflicting information. Can someone who knows licensing really well confirmed this?
    Thank you.

    Hi My3cents,
    Sorry for the delay reply.
    For licensing related issue, you’d better contact Microsoft licensing team. In the United States and Canada, you may call the licensing team directly
    at 1-800-426-9400 (select option 4), Monday through Friday, 6:00 A.M. to 5:30 P.M. (PST) to speak directly to a Microsoft licensing specialist. In this way, you will know the detailed information about license.
    Worldwide customers can use the Guide to Worldwide Microsoft Licensing Sites http://www.microsoft.com/licensing/worldwide.aspx to find contact information
    in their locations.
    Thank you for your understanding!
    Best Regards,
    Anna

  • How many NWDI do we need?

    Hi!
    We are an SAP outsoucing company with many different
    landscapes for MI, EP, ECC, XI, SM, etc.
    We have decided to use NWDI to handle all JAVA change management.
    Some SAP systems can be in the DMZ.
    So how many NWDI do we need? Is one enough?
    I'll give points. Thanks!

    Hi Laura,
    this doc shows typical NWDI scenarios/landscapes with XI
    read just the first section and you will know
    https://www.sdn.sap.com/irj/servlet/prt/portal/prtroot/docs/library/uuid/f85ff411-0d01-0010-0096-ba14e5db6306
    Regards,
    michal
    <a href="/people/michal.krawczyk2/blog/2005/06/28/xipi-faq-frequently-asked-questions"><b>XI / PI FAQ - Frequently Asked Questions</b></a>

  • How many channels should i need for my 10 pieces of thermocouple?

    1.i need test 10 pieces of thermocouples at one time,so how many channels do i need? are 8 channels enough(SCXI-1112) of i must use 32 channel(SCXI-1102)?
    2.I only need test 3 LVDT signals and 3 strain guage signal(must full bridge),do you have 4 channels' LVDT module and 4 channels' Strain/bridge module(full bridge)?
    3.if i hug all these sensors to the signal conditioning,does that mean my DAQ should have at least 16 Analog inputs,beside do you have 12-bit DAQ?

    dittoit,
    1. If you need to measure 10 thermocouples, then you will need at least that many differential channels. So the 1102 would be best.
    2. The current LVDT module we offer is the 1540 which has 8 Channels as does the 1520 which is the best strain gauge module.
    3. The measurements from the SCXI Chassis will normally be multiplexed to one channel on the DAQ card. Any of our E-Series (except the Basic DAQ) will control. Our E-Series card can be either 12-bit or 16-bit.

  • HT1222 How many GB do I need to download video

    How many GB do I need to download video

    It depends on the size of the movie, the capacity of your iPad and how much space you have left, so you need enough to hold whatever the size of the video is and still leave about 10% of your total storage space available.
    Most Movies are at least 2GB. I have seen some that are over 6GB.

  • How many GB do I need to download a rental movie from ITunes?

    How many GB do I need available to download a movie?

    The description in the iTunes Store gives the size of the movie. If you are acquiring it from elsewhere, the information should be available.

  • HT4623 How many gigabytes do I need spare on my iphone4 to upgrade to ios7 ?

    How many gigabytes do I need free on my iphone4 to upgrade to ios7 ?

    Then update using iTunes on your computer. You'll be fine & you don't have to delete anything. You only need that much free space if you update OTA. Once the update is done, you get the space back. So, use your computer.

  • How many WHEREs do we need in minimun when we have 4 FROMs in the statement

    How many WHEREs do we need in minimun when we have 4 FROMs <tables> in the statement?

    Technically none - but it produces cartesian join:
    SQL> SELECT * FROM scott.emp, scott.dept, scott.salgrade;
         EMPNO ENAME      JOB               MGR HIREDATE        SAL       COMM
        DEPTNO     DEPTNO DNAME          LOC                GRADE      LOSAL
         HISAL
          7788 SCOTT      ANALYST          7566 87/04/19       3000
            20         40 OPERATIONS     BOSTON                 3       1401
          2000
          7839 KING       PRESIDENT             81/11/17       5000
            10         40 OPERATIONS     BOSTON                 3       1401
          2000
         EMPNO ENAME      JOB               MGR HIREDATE        SAL       COMM
        DEPTNO     DEPTNO DNAME          LOC                GRADE      LOSAL
         HISAL
    280 wierszy zosta│o wybranych.

  • How many servers are generally needed to a medium size HFM project

    Hi,
    I am new to HFM.Can any one help me that How many servers are generally needed to a medium size HFM project? And details that servers are for what segments?
    Thanks in advance.

    Hi,
    You can use one serwer only for everything (provided that you use classic application).
    Number of servers depends on the number of planned applications, the number of users, number of entities, number of accounts, the amount of calculation...
    Best,
    Marcin Kuzdra

Maybe you are looking for

  • My internet speed

    Ive been with BT for a few months now and there is something i cant really understand. My internet connection says i have 3.1 Kbps but when im trying to download something im only reaching speeds of 240-250Kb/s is there some kind of cap stopping thin

  • Key photos

    Is there a way to change the key photo for an event or to change the name of an event in iPhoto for iOS?

  • What are exit code 6 and exit code 7

    Since the event this afternoon, I have been trying to update the products in CC to 2014.  I keep getting an error without being able to finish installation and get either of the exit codes 6 or 7.  I have tried to troubleshoot by changing to IE (my d

  • How can i send a PDF file to my i phone and be able to read it

    How can i send a PDF file to my i phone and be able to read it

  • Can't edit text in browser

    All my other pages work fine in Business Catalyst editing, but one page won't allow me to edit text boxes. Why?