CSP PKI Hub supports multiple disaster recovery strategies for deploying services across two or more data centers. These strategies range from lower cost and complexity to near-zero recovery time, and can be broadly categorized into three approaches:

Strategy

Operating state

Recovery time

Applicable services

Deploying and recovering services in an Active-Warm Standby architecture

The primary data center is active. The secondary is installed and configured, but with the services stopped.

Minutes (requires service startup and traffic redirection)

All Cryptographic Security Platform services

Deploying services in an Active-Hot Standby architecture

The primary data center is active. The secondary is fully provisioned and continuously running at near-production readiness, but does not actively serve users.

Minutes (requires redeployment of Certificate Authority solution and traffic redirection)

Certificate Authority, Certificate Manager, CA Gateway, Time Stamp Authority (TSA)

Deploying and recovering the OCSP service in an Active-Active architecture

All data centers active and simultaneously serving traffic.

Near-zero (remaining data centers absorb load automatically)

OCSP service (Entrust Validation Authority) for Entrust CA or third-party CAs