Yubico Forum

...visit our web-store at store.yubico.com
It is currently Tue Jan 30, 2018 11:23 am

All times are UTC + 1 hour




Post new topic Reply to topic  [ 3 posts ] 
Author Message
PostPosted: Wed May 07, 2014 2:18 pm 
Offline

Joined: Wed May 07, 2014 2:01 pm
Posts: 2
We want to use YubiX with multiple servers ( with yubico cloud auth and local users database for now).

What the best approach to sync users between servers. So far I am thinking about simple mysql replication from master to slaves but I don't want to to complicate things if "more correct" way available.

Thank you.


Top
 Profile  
Reply with quote  

Share On:

Share on Facebook FacebookShare on Twitter TwitterShare on Tumblr TumblrShare on Google+ Google+

PostPosted: Wed Sep 03, 2014 10:00 pm 
Offline

Joined: Thu Aug 28, 2014 9:24 pm
Posts: 23
Location: California
I have the exact same problem.

I need to setup a couple redundant YubiX instances, with local auth. Obviously, maintaining the keys and users across several separate instances is not desirable. Master/master replication with MySQL might work (via a secure channel, like VPN), but which parts need to be replicated?

Also, there's ykval-queue. Which parts of the database are touched by it? Would master/master replication (configured indiscriminately) break ykval-queue?

Can I just master/master replicate the whole database, and just point the YubiX stack, on each server, at the local MySQL - effectively having a duplicated YubiX server? (same DB structure everywhere, etc.) Then ykval-queue would have to be turned off, right?

YubiX is a very interesting concept, but it's not that useful if there's no clear way to setup multiple redundant servers.

I only need a few pointers, what goes where (so to speak), and I'll try to figure out the rest myself. I'm willing to write a HOWTO and post it on the forum, if only someone could answer my questions above and get me started.

_________________
Florin Andrei
http://florin.myip.org/


Top
 Profile  
Reply with quote  
PostPosted: Fri Sep 05, 2014 11:02 pm 
Offline
Site Admin
Site Admin

Joined: Mon Mar 02, 2009 9:51 pm
Posts: 83
The OTP validating parts can easily be distributed: KSMs need no synchronizing outside of having the YubiKey secrets placed on each of them, and the validation server (YK-KSM) has synchronization built in.

YubiAuth is not yet set up for distributed use, but should work with multiple instances using master/master replication and otherwise identical configuration. I would not recommend having multiple YK-VAL instances using replicated databases however, as this could possibly interfere with the built-in synchronization in unexpected ways.


Top
 Profile  
Reply with quote  
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 3 posts ] 

All times are UTC + 1 hour


Who is online

Users browsing this forum: No registered users and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group