Restoring from a KeyControl backup should only be needed if there is a catastrophic failure in the Cryptographic Security Platform Vault cluster. If one Cryptographic Security Platform Vault node becomes unusable, for example due to hardware failures, simply remove the node from the cluster and add a new node.

Warning: Restore is a destructive process. Any changes made to objects created since the backup image was taken will be lost. This includes keys, policies, and Cryptographic Security Platform Vault user accounts. If the Cryptographic Security Platform Vault SSL certificate was changed since the backup was taken, the older SSL certificate will be restored along with the rest of the system and the current SSL certificate will be discarded.

Custom SSL certificates for internal and external webservers will be restored only if the IP address specified in the certificate matches the Cryptographic Security Platform Vault IP address.

Note: If you are restoring a backup on Cryptographic Security Platform Vault with nShield HSM configured, you must do the following first: 

  • Initialize the Cryptographic Security Platform Vault node that you plan to restore to and copy its keyhash to the clipboard. You will need this keyhash to configure the HSM.

  • Configure the nShield HSM to the new node before you start the restore process.
  • Restore using a backup from the original Cryptographic Security Platform Vault.

  • After the restore process, Cryptographic Security Platform Vault will go through admin key recovery.

  • Select to recover the admin key using HSM.

  • Provide the softcard name and softcard password used on the Cryptographic Security Platform Vault where the backup was created.

  • After recovery, log in to the newly deployed Cryptographic Security Platform Vault and check that the admin key is available in the HSM.

Procedure 

  1. Log into the Cryptographic Security Platform Vault Management webGUI using an account with Security Admin privileges.
  2. In the top menu bar, click Cluster.
  3. If there are any other nodes in this cluster, you must remove them before you restore the node. To do so:

    1. Click on the Servers tab.
    2. Click on each of the other nodes in the cluster and select Actions > Remove.
    3. Click Proceed at the prompt to confirm the request.
  4. Go to the Cluster tab.
  5. Select Actions > Restore.
  6. Click Browse and select the backup file from which you want to restore Cryptographic Security Platform Vault. The name of the selected file appears next to the Browsebutton.
  7. Click Verify Image. Cryptographic Security Platform Vault uploads the file and verifies that it is a valid backup file. It also displays a hint stating which Admin Key generation count goes with this backup file in case you need to upload the matching Admin Key parts. For example:

    Hint: Keypart generation version for this backup image is 16.

    For details, see Admin Keys.

  8. Click Restore Image.
  9. Click Proceed at the prompt to confirm the request. Cryptographic Security Platform Vault restores the system information from the backup file and reboots the server.
  10. Verify the restoration by logging back into the Cryptographic Security Platform Vault Management webGUI.

    Important: Remember that all user account information has been reverted back to whatever it was when the backup was taken. That means your account may not exist or that the password may have changed.

  11. If the hardware has changed since the backup was taken, Cryptographic Security Platform Vault presents you with additional options.

    Option

    Description

    Recovery using Keypart upload

    Allows you to recover the Admin key by uploading the parts from local files. You must upload the required number of parts of the Admin key within 10 minutes to use this method.

    Important: All Admin key parts must have the key generation count that was valid when the back up was taken. For details, see Admin Keys.

    Recovery from External key server

    Allows you to recover the Admin key by connecting to a server or HSM (Hardware Security Module).

    Decommission

    Tells Cryptographic Security Platform Vault to decommission the server. For more information, see Decommissioning a Cryptographic Security Platform Vault Node.

  12. If you removed any nodes from the cluster, re-join them as described in Joining or Re-joining a Cryptographic Security Platform Vault Cluster.