The two instances of OpenSSO Enterprise are fronted by one load balancer (Load Balancer 2). Users will access OpenSSO Enterprise through the secure port 1081. Load Balancer 2 sends the user and agent requests to the server where the session originated. Secure Sockets Layer (SSL) is terminated and regenerated before a request is forwarded to the OpenSSO Enterprise servers to allow the load balancer to inspect the traffic for proper routing. Load Balancer 2 is capable of the following types of load balancing:
| Cookie-based | The load balancer makes decisions based on client's cookies. The load balancer looks at the request and detects the presence of a cookie by a specific name. If the cookie is detected in the request, the load balancer routes the request to the specific server to which the cookie has been assigned. If the cookie is not detected in the request, the load balancer balances client requests among the available servers. | 
| IP-based | This is similar to cookie-based load balancing, but the decision is based on the IP address of the client. The load balancer sends all requests from a specific IP address to the same server. | 
| TCP | The load balancer mainstreams session affinity. This means that all requests related to a TCP session, are forwarded to the same server. In this deployment example, Load Balancer 2 forwards all requests from a single client to exactly the same server. When the session is started and maintained by one client, session affinity is guaranteed. This type of load-balancing is applicable to the TCP-based protocols. | 
This section assumes that you have already installed a load balancer. Before you begin, note the following:
The load balancer hardware and software used in the lab facility for this deployment is BIG-IP® manufactured by F5 Networks. If you are using different load balancer software, see the documentation that comes with that product for detailed settings information.
Contact your network administrator to obtain an available virtual IP address for the load balancer you want to configure.
Know the IP address of the load balancer hardware, the URL for the load balancer login page, and a username and password for logging in to the load balancer application.
Get the IP addresses for OpenSSO Enterprise 1 and OpenSSO Enterprise 2 by running the following command on each host machine:
| # ifconfig -a | 
Use the following list of procedures as a checklist for completing the task.
To Request a Certificate for OpenSSO Enterprise Load Balancer 2
To Install a CA Root Certificate to OpenSSO Enterprise Load Balancer 2
To Install the Server Certificate to OpenSSO Enterprise Load Balancer 2
To Create an SSL Proxy for SSL Termination at the OpenSSO Enterprise Load Balancer 2
 To Request a Certificate for OpenSSO Enterprise Load Balancer
2
To Request a Certificate for OpenSSO Enterprise Load Balancer
2You should already have a root certificate from the CA of your choice. Generate a request for a server certificate to send to the CA. For more information, see 3.3 Obtaining Secure Socket Layer Certificates.
Access https://is-f5.siroe.com, the BIG-IP load balancer login page, in a web browser.
Log in to the BIG-IP console as the administrator.
Click Configure your BIG-IP (R) using the Configuration Utility.
In the left pane, click Proxies.
Click the Cert-Admin tab.
On the SSL Certificate Administration page, click Generate New Key Pair/Certificate Request.
In the Create Certificate Request page, provide the following information.
lb2.sp-example.com
Deployment
lb2.sp-example.com
password
password
Click Generate Key Pair/Certificate Request.
On the SSL Certificate Request page, the request is generated in the Certificate Request field.
Save the text contained in the Certificate Request field to a file named lb-2.csr.
Log out of the console and close the browser.
Send lb-2.csr to the CA of your choice.
The CA issues and returns a signed server certificate named lb-2.cer.
 To Install a CA Root Certificate to OpenSSO Enterprise Load
Balancer 2
To Install a CA Root Certificate to OpenSSO Enterprise Load
Balancer 2Install the CA root certificate on Load Balancer 2 to ensure that a link between it and the CA can be maintained. Use the same root certificate that you imported in 7.4 Enabling Secure Communication for the Directory Server User Data Instances. For more information, see 3.3 Obtaining Secure Socket Layer Certificates.
Access https://is-f5.example.com, the BIG-IP load balancer login page, in a web browser.
Log in to the BIG-IP console as the administrator.
In the BIG-IP load balancer console, click Proxies.
Click the Cert-Admin tab.
Click Import.
In the Import Type field, choose Certificate, and click Continue.
Click Browse in the Certificate File field on the Install SSL Certificate page.
In the Choose File dialog, choose Browser.
Navigate to ca.cer and click Open.
In the Certificate Identifier field, enter openSSLCA.
Click Install Certificate.
On the Certificate openSSLCA page, click Return to Certificate Administration.
The root certificate named openSSLCA is now included in the Certificate ID list.
 To Install the Server Certificate to OpenSSO Enterprise Load
Balancer 2
To Install the Server Certificate to OpenSSO Enterprise Load
Balancer 2This procedure assumes you have received the CA-signed server certificate requested in To Request a Certificate for OpenSSO Enterprise Load Balancer 2, just completed To Install a CA Root Certificate to OpenSSO Enterprise Load Balancer 2, and are still logged into the load balancer console.
In the BIG-IP load balancer console, click Proxies.
Click the Cert-Admin tab.
The key lb2.sp-example.com is in the Key List.
In the Certificate ID column, click Install for lb2.sp-example.com.
In the Certificate File field, click Browse.
In the Choose File dialog, navigate to lb-2.cer, the CA-signed server certificate, and click Open.
Click Install Certificate.
On the Certificate lb2.sp-example.com page, click Return to Certificate Administration Information.
Verify that the Certificate ID indicates lb2.sp-example.com on the SSL Certificate Administration page.
Log out of the load balancer console.
 To Configure OpenSSO Enterprise Load Balancer 2
To Configure OpenSSO Enterprise Load Balancer 2Access https://is-f5.example.com, the BIG-IP load balancer login page, in a web browser.
Log in to the BIG-IP console as the administrator.
Click Configure your BIG-IP (R) using the Configuration Utility.
Create a Pool.
A pool contains all the backend server instances.
In the left pane, click Pools.
On the Pools tab, click Add.
In the Add Pool dialog, provide the following information.
OpenSSO-SP-Pool
Round Robin
Add the IP addresses and port numbers for both OpenSSO Enterprise host machines.
Use port number 1081.
Click Done.
Add a Virtual Server.
The virtual server presents an address to the outside world and, when users attempt to connect, it would forward the connection to the most appropriate real server.
If you encounter JavaScriptTM errors or otherwise cannot proceed to create a virtual server, try using Internet Explorer.
In the left frame, click Virtual Servers.
On the Virtual Servers tab, click Add.
In the Add a Virtual Server dialog box, provide the following information:
Enter the IP address for lb2.sp-example.com
1082
Continue to click Next until you reach the Pool Selection dialog box.
In the Pool Selection dialog box, assign the OpenSSO-SP-Pool Pool.
Click Done.
Add Monitors.
OpenSSO Enterprise comes with a JSP file named isAlive.jsp that can be contacted to determine if the server is down. Since we have not yet deployed OpenSSO Enterprise, isAlive.jsp cannot be used. In the following sub procedure, create a custom monitor that periodically accesses the Application Server instance(s). If desired, the monitor can be changed later to use isAlive.jsp.
Click the Monitors tab
Click the Basic Associations tab
Find the IP address for osso1.sp-example.com:1080 and osso2.sp-example.com:1080.
Mark the Add checkbox that corresponds to the IP address for both osso1.sp-example.com:1080 and osso2.sp-example.com:1080.
At the top of the Node column, choose the tcp monitor.
Click Apply.
Configure the load balancer for persistence.
In the left pane, click BIGpipe.
In the BIGpipe command window, type the following:
| makecookie ip-address:port | 
ip-address is the IP address of the osso1.sp-example.com host machine and port is the same machine's port number; in this case, 1081.
Press Enter to execute the command.
Something similar to Set-Cookie: BIGipServer[poolname]=692589248.36895.0000; path=/ is displayed. Save the numbered value (in this case, 692589248.88888.0000) for use in To Create a Site on OpenSSO Enterprise 1.
In the left pane, click BIGpipe again.
In the BIGpipe command window, type the following:
| makecookie ip-address:port | 
ip-address is the IP address of the osso2.sp-example.com host machine and port is the same machine's port number; in this case, 1081.
Press Enter to execute the command.
Something similar to Set-Cookie: BIGipServer[poolname]=692589248.12345.0000; path=/ is displayed. Save the numbered value (in this case, 692589248.99999.0000) for use in To Create a Site on OpenSSO Enterprise 1.
Log out of the load balancer console.
 To Create an SSL Proxy for SSL Termination
at the OpenSSO Enterprise Load Balancer 2
To Create an SSL Proxy for SSL Termination
at the OpenSSO Enterprise Load Balancer 2SSL communication is terminated at Load Balancer 2. The request is then re-encrypted and securely forwarded to OpenSSO Enterprise. When clients send an SSL-encrypted request to Load Balancer 2, it decrypts the request and re-encrypts it before sending it on to the OpenSSO Enterprise SSL port. Load Balancer 2 also encrypts the responses it receives back from OpenSSO Enterprise, and sends these encrypted responses back to the client. Towards this end create an SSL proxy for SSL termination and regeneration.
Use the same root certificate that you imported in 7.4 Enabling Secure Communication for the Directory Server User Data Instances. For more information, see 3.3 Obtaining Secure Socket Layer Certificates.
Access https://is-f5.example.com, the BIG-IP load balancer login page, in a web browser.
Log in to the BIG-IP console as the administrator.
Click Configure your BIG-IP (R) using the Configuration Utility.
In the left pane, click Proxies.
Under the Proxies tab, click Add.
In the Add Proxy dialog, provide the following information.
Check the SSL and ServerSSL checkbox.
The IP address of Load Balancer 2.
1081
The secure port number
The IP address of Load Balancer 2.
1082
The non-secure port number
Choose Local Virtual Server.
Choose lb2.sp-example.com.
Choose lb2.sp-example.com.
Check this checkbox.
Click Next.
On the page starting with “Insert HTTP Header String,” change to Rewrite Redirects and choose Matching.
Click Next.
On the page starting with “Server Chain File,” change to Server Trusted CA's File, select “ca.cer” from the drop-down list.
Click Done.
The new proxy server is added to the Proxy Server list.
Log out of the load balancer console.
Access https://lb2.sp-example.com:1081/index.html from a web browser.
If the Application Server index page is displayed, you can access it using the new proxy server port number and the load balancer is configured properly.
A message may be displayed indicating that the browser doesn't recognize the certificate issuer. If this happens, install the CA root certificate in the browser so that the browser recognizes the certificate issuer. See your browser's online help system for information on installing a root CA certificate.
Close the browser.