Symantec Access Management

 View Only
  • 1.  CA Directory (LDAP) failover configuration for CA Strong Authentication

    Posted Jul 21, 2020 06:21 AM
    Edited by Samarendra Routray Jul 21, 2020 07:11 AM
    Hi,

    I have integrated CA Directory with CA Strong Authentication server by creating organization following the below link.

    https://techdocs.broadcom.com/content/broadcom/techdocs/us/en/ca-enterprise-software/layer7-identity-and-access-management/advanced-authentication/9-1/administrating/administrating-ca-strong-authentication/create-organization-in-ldap-repository.html

    Here I can integrate only one directory server for one organization.
    I want to configure directory server (user store) failover for Strong Authentication server, where if one directory server is stopped, it could get user's from the other directory.

    Is there any way / options where we can able to use/integrate multiple directory server DSA those are in replication with the CA Strong Authentication server for a single organization while creating organization.

    Please let me know if it is possible.

    Thank you,
    Regards,
    Samarendra Routray


  • 2.  RE: CA Directory (LDAP) failover configuration for CA Strong Authentication

    Posted Jul 21, 2020 10:26 AM
    One option which I could think of is, having a  LB or VIP or even a router DSA in front of DSA servers and configure it in AA.



  • 3.  RE: CA Directory (LDAP) failover configuration for CA Strong Authentication

    Broadcom Employee
    Posted Jul 22, 2020 08:08 AM
    As Ashok mentioned, if you decide to go with Symantec Directory router DSA, you can refer to Symantec Directory product documentation. Here are some samples that can assist you to get started with:

    https://techdocs.broadcom.com/content/broadcom/techdocs/us/en/ca-enterprise-software/layer7-identity-and-access-management/directory/14-1/ca-directory-concepts/directory-distribution-and-routing/dsas-with-same-prefix.html

    https://techdocs.broadcom.com/content/broadcom/techdocs/us/en/ca-enterprise-software/layer7-identity-and-access-management/directory/14-1/ca-directory-concepts/directory-distribution-and-routing/improving-the-routing-performance.html

    ~Hitesh


  • 4.  RE: CA Directory (LDAP) failover configuration for CA Strong Authentication

    Broadcom Employee
    Posted Jul 22, 2020 03:44 PM
    CA Advanced authentication supports single configuration for external repositories, you can use a Load Balanced External repository details for high availability but there is no failover logic in product for this.

    -Namish


  • 5.  RE: CA Directory (LDAP) failover configuration for CA Strong Authentication

    Posted Nov 04, 2020 02:11 PM
    Load Balancer can do the failover & load balancing. If one of the user store is not up and running then LB can identify that with health monitoring and mark that user store offline.