BlueCat strongly recommends clustering at least two HSM servers for failover and disaster recovery.
Important: If the primary HSM fails for any reason, failover to the
standby HSM server occurs automatically. If this happens the
secondary HSM will automatically be promoted to primary status.
With BlueCat versions older than 25.1, when the failed HSM
resumes normal operation, BIND must be re-started to complete
the failover from the original secondary HSM back to the
original primary HSM. In BlueCat version 25.1 and newer, BIND
does not need to be restarted to complete the failover process
from the original secondary HSM back to the original primary
HSM.This limitation is not present with BlueCat 25.1 as it
utilizes the Entrust Security World Client version 13.6.5, which
corrected this failback limitation.