Restoring KeyControl Through the webGUI

Restoring from a KeyControl backup should only be needed if there is a catastrophic failure in the KeyControl cluster. If one KeyControl node becomes unusable, for example due to hardware failures, simply remove the node from the cluster and add a new node.

Warning: Restore is a destructive process. Any changes made to objects created since the backup image was taken will be lost. This includes keys, policies, and KeyControl user accounts. If the KeyControl SSL certificate was changed since the backup was taken, the older SSL certificate will be restored along with the rest of the system and the current SSL certificate will be discarded.

  1. Log into the KeyControl webGUI using an account with Domain Admin privileges.
  2. In the top menu bar, click Cluster.
  3. If there are any other nodes in this cluster, you must remove them before you restore the node. To do so:

    1. Click on the Servers tab.
    2. Click on each of the other nodes in the cluster and select Actions > Remove.
    3. Click Proceed at the prompt to confirm the request.
  4. Go to the Cluster tab.
  5. Select Actions > KeyControl Restore.
  6. Click Browse and select the backup file from which you want to restore KeyControl. The name of the selected file appears next to the Browse button.
  7. Click Verify Image. KeyControl uploads the file and verifies that it is a valid backup file. It also displays a hint stating which Admin Key generation count goes with this backup file in case you need to upload the matching Admin Key parts. For example:

    Hint: Keypart generation version for this backup image is 16.

    For details, see Admin Keys.

  8. Click Restore Image.
  9. Click Proceed at the prompt to confirm the request. KeyControl restores the system information from the backup file and reboots the server.
  10. Verify the restoration by logging back into the KeyControl webGUI.

    Important: Remember that all user account information has been reverted back to whatever it was when the backup was taken. That means your account may not exist or that the password may have changed.

  11. If the hardware has changed since the backup was taken, KeyControl presents you with additional options.

  12. If you removed any nodes from the cluster, re-join them as described in Joining or Re-joining a KeyControl Cluster.