Sentinel LDK-EMS Network Configuration Options
Sentinel LDK-EMS is a web-based, multi-tier application with two primary components: Sentinel LDK-EMS Service and the Sentinel LDK-EMS database. These components can be installed on a single machine or on separate machines (server).
The web application front end in Sentinel LDK-EMS Service provides two portals, one for software vendor users and another for customers (primarily for activation purposes). Sentinel LDK-EMS Service can be installed and configured for each portal on a separate machine. (This is not a typical configuration for web applications.)
Based on the vendor requirements, a number of security provisions are possible for Sentinel LDK-EMS installation. Instances of Sentinel LDK-EMS are usually installed on a DMZ (demilitarized zone) using an external firewall that controls external access, and an internal firewall that allows access to the Sentinel LDK-EMS database.
Sentinel LDK-EMS listens on a TCP port for incoming requests. If the installation is configured for SSL, the requests are encrypted using the built-in SSL feature. Sentinel LDK-EMS then communicates with the Sentinel LDK-EMS database (a single database for the entire system) to process the requests.
This section describes the considerations and procedures for installing the Sentinel LDK-EMS components, including different configurations for installing Sentinel LDK-EMS on multiple machines in a network environment.
NOTE Thales recommends that you:
>Frequently back up your Sentinel LDK-EMS database to protect your data.
>Add adequate security measure including SSL communication link and a firewall to protect your data and application.
In this section:
>Standard Production Configuration for Sentinel LDK-EMS
Installation of Sentinel LDK-EMS Service and the Sentinel LDK-EMS database on two separate machines.
>Sentinel LDK-EMS Web Portals on Separate Servers
Installation of the Sentinel LDK-EMS Vendor web portal and the Customer web portal on two separate machines. The Sentinel LDK-EMS database is installed together with the Vendor web portal or on a third machine.