Webconf: Restore
Prerequisites
The Next Generation Hardware Appliance needs to be in Alarm State or Factory Reset State.
For u.trust HSM
A Backup with its DMS and the corresponding Backup Protection Smart Cards.
A connected PIN Pad to interact with the HSM restore.
SCA Cards are a prerequisite for recovery if the backup setup has SCA enabled slots.
For Luna HSM
A Backup with its DMS and the corresponding Backup Keys.
A locally or externally connected Backup Device to interact with the HSM restore.
Do not restart or shut down the appliance while the Restore is running.
To restore the Next Generation Hardware Appliance from an existing backup, perform the following steps:
Log in to the Next Generation Hardware Appliance.
Open the Restore page.
In the Restore Settings section select the Network File Setting (NFS) option from the drop down menu under Storage Type.
Enter your NFS URL and click Browse Storage to open the Storage Browser:
Navigate to the path where the backup is located. Click on Directories to navigate one level down or click .. One level up to return to the previous level.
Select the backup you want to restore.
Provide the Domain Master Secret (DMS).
Click Restore Now to open the corresponding form.
The form contains all the important information about the selected backup to be restored.
For u.trust HSM
Be aware, that you will need to perform PIN Pad interactions in several steps during HSM restore.
To proceed click Restore.
Follow the instructions in the Restore Guide.
The Restore Guide/Wizard appears in Webconf and guides through the next steps.
It shows the overall progress and indicates the part, that is currently restored.
It is possible that a restore fails in a certain step. In this case, a Retry button is displayed. Click on this button to repeat the failed restore step.
The Restore is successful.
For Luna HSM
This restore process only restores the database and the configuration data of the appliance.
The HSM Restore process must be carried out separately from the Security page.
Restoring a Migration Backup from a Legacy Hardware Appliance
To restore a Migration Backup from the Legacy Hardware Appliance, proceed as for Restore.
Make sure to navigate to the path where the Migration Backup from the Legacy Hardware Appliance is located.
Select the backup you want to restore and proceed as described above.
The appliance must now be rebooted to complete the migration.
If the restore is carried out while retaining the current network, an error may occur in the Transport Layer Security (TLS) interface, which can be rectified manually.
In the TLS display, the active interface may only be displayed in one domain. This can be corrected manually. The page Transport Layer Security (TLS) shows you how to manage TLS certificates in Webconf.
After the migration, old SCA Cards will continue to work with all slots on which SCA was activated.
If the SCA configuration of a slot is adjusted, new, individual SCA Users are generated for this slot. These new SCA Users will only work on the new slot, not on the already existing slots on which SCA was activated.