6.2

Table Of Contents
For workload distribution and failover, you may place multiple vRealize Appliances behind a load
balancer. In addition, you may place multiple IaaS Web servers and multiple IaaS Manager Service
servers behind their respective load balancers.
When using load balancers, do not allow the load balancers to send health checks at any time during
installation. Health checks might interfere with installation or cause the installation to behave
unpredictably.
n
When deploying vRealize Appliance or IaaS components behind existing load balancers, disable
health checks on all load balancers in the proposed configuration before installing any components.
n
After installing and configuring all of vRealize Automation, including all vRealize Appliance and IaaS
components, you may re-enable health checks.
Certificate Trust Requirements in a Distributed
Deployment
For secure communication, vRealize Appliance relies on certificates to create the trusted relationships
between components.
The specific implementation of the certificates required to achieve this trust depends on your
environment.
To provide high availability and failover support, you might deploy load balanced clusters of components.
In this case, you obtain a multi-use certificate that includes each component in the cluster, and then copy
that multi-use certificate to each component in the cluster. You can use Subject Alternative Name (SAN)
certificates, chain certificates, wildcard certificates, or any other method of multi-use certification
appropriate for your environment as long as you satisfy the trust requirements. Depending on your load
balancer configuration, you may need to certify the load balancer as part of the multi-use certificate for
the cluster.
For example, if you have a load balancer configuration that requires a certificate on the load balancer as
well as its components, you might obtain a SAN certificate to certify web-load-
balancer.eng.mycompany.com, web-component-1.eng.mycompany.com, and web-
component-2.eng.mycompany.com. You would copy that single multi-use certificate to the load balancer
and each of the appliances and then register the certificate on the Web component machines.
The Trust Requirements diagram illustrates the required trust relationships among clusters and assumes
you have configured trust as necessary between the load balancer and the nodes underneath it.
Installation and Configuration
VMware, Inc. 57