After any change to the PKI Hub cluster 1 configuration, perform the steps below to restore PKI Hub cluster 1 configuration on PKI Hub cluster 2.
To restore the PKI Hub 1 configuration on PKI Hub 2
- Run the clusterctl backup create command on any node of PKI Hub cluster 1.
- Copy the generated file to PKI Hub cluster 2.
- Use this file to run the clusterctl backup restore on any node of PKI Hub cluster 2.
- Export the
kmdatafrom the nShield RFS (Remote File System) on the passive datacenter. - Log in to the Management Console of any node of the passive datacenter.
- Select the HSM tab of the Certificate Authority configuration page.
- Export the current file in the nShield kmdata tar file field.
- Extract the PKI Hub wrapping key from the exported file.
- Add this PKI Hub key to the
kmdataexported from the nShield RFS. - Click Choose File and select the modified
kmdatafile to update the file in the nShield kmdata tar file field.