We would like to set up IA between 2 clusters managed by different management domain servers and our first thought was to go with IA sharing. We checked IA Admin Guide and everything seemed pretty straight forward until I stumble across another SK about establishing SIC between IA entities handled by different management domain servers which will complicate the config. (specially with repeating several steps with each upgrade of PDP or PEP).
If identity sharing set up will be too complicated, there is still the possibility to use separate IA on each cluster.
In that case, we will also replicate the access role in both clusters and we were wondering if we can use the same Terminal Servers for both clusters? (with the same preshared key)