fabric icon indicating copy to clipboard operation
fabric copied to clipboard

Implement distribution of CA from Membership Services accross different servers

Open dulcep opened this issue 8 years ago • 8 comments

Consider splitting the CAs to allow them to be distributed across different servers / ports, and potentially add local admin interfaces. This allows to have each CA running on a different machine and also be able to run multiple instances of each CA

dulcep avatar Mar 30 '16 01:03 dulcep

Could we have a use-case to clarify this issue. I would prefer decentralized rather than distributed, but you might have meant the same thing.

binhn avatar Mar 30 '16 21:03 binhn

Currently the problem is: the CA server is a single point of failure, we could not find any document in obc-doc guide us to setup a HA or decentralized whatever CA server env. @binhn: Do we have any solution or plan on this?

genggjh avatar Mar 31 '16 01:03 genggjh

@adecaro @elli-androulaki could we deploy CA server in a hot stand-by?

binhn avatar Mar 31 '16 16:03 binhn

Binh - yes, I meant decentralized, as not having a single point of failure

dulcep avatar Apr 02 '16 04:04 dulcep

@genggjh yes, working on the design of that; we'll post something soon in the wiki, so please watch that and collaborate.

binhn avatar Apr 09 '16 15:04 binhn

Just wanted to add a comment to emphasize the importance, from my point of view, of this issue. HyperLedger is designed to work with a network of distrusting peers, if a centralized CA is needed then a trusted peer (by all peers) has to be added, which turns blockchain into a centralized network.

mcr222 avatar Apr 11 '16 14:04 mcr222

Can we add a new labels of Identity & CA and associate this?

markparz avatar Apr 16 '16 15:04 markparz

Did this issue evolve ? I'm new to CA and don't know if it possible today to create a decentralized ca. Can someone point me to some extra information in the doc?

Thank you

GuillaumeCisco avatar Oct 16 '17 16:10 GuillaumeCisco