Backing up and Restoring Certificate System
99
•
Internal database.
The Directory Server provides its own back up scripts and procedures; see the
Directory Server documentation for more information on backing up the LDAP database.
•
Security databases.
The security databases store the certificate and key material. If these are stored
on an HSM, then consult the HSM vendor documentation for information on how to back up the
data. If the information is stored in the default directories in the instance
alias
directory, then it is
backed up with the instance directory. To back it up separately, use a utility such as
tar
or
zip
.
•
Instance directory.
The instance directory contains all configuration files, security databases, and
other instance files. This can be backed up using a utility such as
tar
or
zip
.
For example, back up the
alias
directory or the instance directory:
1. Stop the subsystem instance.
/etc/init.d/
instance_ID
stop
2. Save the directory to a compressed file. For example:
cd /var/lib/rhpki-ca/
tar -cvf /export/archives/ca/alias.tar alias/
3. Restart the subsystem instance.
/etc/init.d/
instance_ID
start
NOTE
Stop the subsystem instance before backing up the instance or the security databases.
The Directory Server database can be restored using Directory Server-specific tools; see the Directory
Server documentation for more information on restoring the LDAP database.
The Certificate System backup files, both the
alias
database backups and the full instance directory
backups, can be used to replace the current directories if the data are corrupted or hardware is
damaged. To restore the data, uncompress the archive file using the
unzip
or
tar
tool, and copy the
archive over the existing files.
To restore the
alias
directory or the instance directory:
1. Uncompress the archive; for example, untar an
alias
directory archive:
cd /export/archive/ca/
tar -xvf alias.tar
2. Stop the subsystem instance if it has not already been stopped.
/etc/init.d/
instance_ID
stop
Содержание CERTIFICATE SYSTEM 7.2 - MIGRATION GUIDE
Страница 36: ...Chapter 1 Overview 16 Figure 1 4 Certificate System Architecture ...
Страница 144: ...124 ...
Страница 160: ...140 ...
Страница 208: ...188 ...
Страница 210: ...190 ...
Страница 256: ...236 ...
Страница 282: ...Chapter 12 Certificate Profiles 262 Parameter IssuerName_n IssuerType_n ...
Страница 285: ...Freshest CRL Extension Default 265 Parameter PointName_n PointIssuerName_n ...
Страница 335: ...Configuring Mappers 315 Figure 14 9 Selecting a New Mapper Type 6 Edit the mapper instance and click OK ...
Страница 362: ...342 ...
Страница 376: ...356 ...
Страница 436: ...416 ...
Страница 490: ...470 ...
Страница 504: ...484 ...