<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=31&amp;t=1381" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2014-09-05T23:02:04+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=31&amp;t=1381</id>
<entry>
<author><name><![CDATA[dain]]></name></author>
<updated>2014-09-05T23:02:04+01:00</updated>
<published>2014-09-05T23:02:04+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1381&amp;p=5540#p5540</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1381&amp;p=5540#p5540"/>
<title type="html"><![CDATA[Re: [QUESTION] sync between servers]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1381&amp;p=5540#p5540"><![CDATA[
The OTP validating parts can easily be distributed: KSMs need no synchronizing outside of having the YubiKey secrets placed on each of them, and the validation server (YK-KSM) has synchronization built in.<br /><br />YubiAuth is not yet set up for distributed use, but should work with multiple instances using  master/master replication and otherwise identical configuration. I would not recommend having multiple YK-VAL instances using replicated databases however, as this could possibly interfere with the built-in synchronization in unexpected ways.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=504">dain</a> — Fri Sep 05, 2014 11:02 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[FlorinAndrei]]></name></author>
<updated>2014-09-03T22:00:19+01:00</updated>
<published>2014-09-03T22:00:19+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1381&amp;p=5539#p5539</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1381&amp;p=5539#p5539"/>
<title type="html"><![CDATA[Re: [QUESTION] sync between servers]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1381&amp;p=5539#p5539"><![CDATA[
I have the exact same problem.<br /><br />I need to setup a couple redundant YubiX instances, with local auth. Obviously, maintaining the keys and users across several separate instances is not desirable. Master/master replication with MySQL might work (via a secure channel, like VPN), but which parts need to be replicated?<br /><br />Also, there's ykval-queue. Which parts of the database are touched by it? Would master/master replication (configured indiscriminately) break ykval-queue?<br /><br />Can I just master/master replicate the whole database, and just point the YubiX stack, on each server, at the local MySQL - effectively having a duplicated YubiX server? (same DB structure everywhere, etc.) Then ykval-queue would have to be turned off, right?<br /><br />YubiX is a very interesting concept, but it's not that useful if there's no clear way to setup multiple redundant servers.<br /><br />I only need a few pointers, what goes where (so to speak), and I'll try to figure out the rest myself. I'm willing to write a HOWTO and post it on the forum, if only someone could answer my questions above and get me started.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2986">FlorinAndrei</a> — Wed Sep 03, 2014 10:00 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[nvitaly]]></name></author>
<updated>2014-05-07T14:18:18+01:00</updated>
<published>2014-05-07T14:18:18+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1381&amp;p=5251#p5251</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1381&amp;p=5251#p5251"/>
<title type="html"><![CDATA[[QUESTION] sync between servers]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1381&amp;p=5251#p5251"><![CDATA[
We want to use YubiX with multiple servers ( with yubico cloud auth and local users database for now).<br /><br />What the best approach to sync users between servers. So far I am thinking about simple mysql replication from master to slaves but I don't want to to complicate things if &quot;more correct&quot; way available.<br /><br />Thank you.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2904">nvitaly</a> — Wed May 07, 2014 2:18 pm</p><hr />
]]></content>
</entry>
</feed>