This guide covers two standard deployment scenarios. At no time will traffic destined for the Virtru Private Keystore (for Virtru Solutions) traverse any network as plain text.
All traffic will be encrypted via TLS by a Public Certificate Authority (CA) signed certificate.
Scenario 1 - TLS Termination at Virtru Private Keystore
In this scenario, all traffic between the Virtru Key Server and the Virtru Private Keystore (for Virtru Solutions) is encrypted and cannot be decrypted. The there is no way to decrypt and monitor the traffic in this scenario.
Load Balancing
Load balancing in this scenario can be performed inside or outside a firewall by either an active or passive load balancing scheme.
Active
- Hardware Load Balancer
- Software Load Balancer
Passive
- DNS Round Robin
Scenario 2 - TLS Termination at Load Balancer
In this scenario, the traffic between the Virtru Key Server and the Virtru Private Keystore is encrypted via TLS. The traffic is initiated at the Virtru Key Server and terminates at the Load Balancer. The traffic can be inspected and monitored from the load balancer. A TLS connection is initiated from the Load Balancer to the Virtru Private Keystore and terminates on the Virtru Private Keystore.
Load Balancing
Load balancing in this scenario can be performed inside or outside a firewall by an active load balancer only. This limitation is introduced due to reinitiating a TLS connection.
Additional Considerations
The certificate on the load balancer must be signed by a Certificate Authority (CA).
Active
- Hardware Load Balancer
- Software Load Balancer
Load Balancer TLS Configuration
If you deploy the Virtru Private Keystore behind a load balancer (LB), the LB must re-encrypt traffic to the Virtru Private Keystore nodes using a standard, modern TLS profile. The Virtru Private Keystore terminates TLS on each node and will reject handshakes that offer only legacy or weak cipher suites.
Note that this applies to the server-side TLS profile — the one governing the connection between the LB and the Virtru Private Keystore node — not the client-facing profile that handles inbound connections to the load balancer's virtual server.
Use your LB's default or standard server-side TLS profile. Avoid legacy or "compatibility mode" profiles: despite names implying broader interoperability, these typically enable an older cipher list the Virtru Private Keystore does not accept, and applying one results in SSL handshake failures between the LB and the node(s).
These failures commonly surface immediately after a Virtru Private Keystore version upgrade, when a newer build tightens its accepted cipher suites and a previously working legacy profile stops negotiating. If you run multiple keystore nodes behind the load balancer, apply the same server-side TLS profile to every pool member, and disable a node in the pool before upgrading it so traffic drains cleanly to the remaining node.