Overview
Use this document to create a backup file of your data security manager.
Before you upgrade to Generation 4, Armor recommends that you create a backup file.
Before you begin:
- You must have system administrator credentials to access the Vormetric DSM
- You must be able to connect to your Cisco AnyConnect VPN client in order to reach the DSM's public IP address over an https:// connection.
At a high level, this process includes five major steps:
- Create a new system administrator
- Create an asymmetric wrapper key
- Export the wrapper key
- Download the encrypted DSM configuration file
- Restore the DSM with the configuration file
Step 1: Create the wrapper key custodian
- Log into the DSM console as the system administrator (admin).
- Click the Administrators tab. (You can ignore the drop-down menu that appears.)
- Click Add to create a new administrator.
- Click the Administrators tab. (You can ignore the drop-down menu that appears.)
- In Login, enter a user name that you will use to log into the DMS.
- (Optional) In Description, enter an easily identifiable description.
- You can leave the RSA User ID field blank.
- In Password and ConfirmPassword, enter a password.
- Armor recommends that you enter a temporary password because after you log into the DSM as the system administrator, you will be asked to change your password.
- In User Type, select System Administrator.
- Make sure the Read-Only User box is unmarked.
- Click Ok.
Step 2: Create a wrapper key
- In the top menu bar, select System.
- In the drop down menu, select Wrapper Keys.
- In Operation drop-down menu, select Create.
- Click Apply.
Step 3: Export Wrapper Key
- In the Operation drop-down menu, select Export.
- In the window that appears, for Minimum Custodians Needed, enter 1.
- For Total number of Custodians, enter 1.
- In the table, mark the newly created Wrapper Key Custodian.
- Click Apply. The Wrapper Key has now been exported to the Wrapper Key Custodian.
- Log out the DSM as the administrator.
- Log into the DSM as the Wrapper Key Custodian.
- When you log into the DSM as the Wrapper Key Custodian, you will be asked to create a permanent password.
- h
- h
- h
- h
Step 3: Download the encrypted DSM configuration file
- Log out of the DSM as the Wrapper Key Custodian, and then log into the DSM as the admin.
- In the top menu bar, click Systems.
- Click Backup and Restore, and then select Manual Backup and Restore.
Click Ok. The backup configuration file will download to your local machine.
Step 4: Restore the wrapper key and configuration file
- Log into the DMS as the Wrapper Key Custodian.
- In the top bar, click Systems, and then select Wrapper Keys.
- Next to Operation, in the drop-down menu, select Import.
- Click Add.
- In the window that appears, in Key Share, enter the wrapper key share.
- Click Ok.
- In the window that appears, the wrapper key share will populate the field. For this wrapper key share, mark the Selected column.
- Click Apply.
- Log out of the DSM.
Step 5: Restore (upload) the DSM configuration file.
- Log in the DSM as the system administrator (admin).
- In the top menu, click Systems.
- Select Backup and Restore, and then select Manual Backup and Restore.
- Click Restore.
- Click Browse to locate and select the DSM configuration file.
- Click OK.
- After you click OK, you will be logged out of the DSM.
- After you click OK, you will be logged out of the DSM.
- Log back into the DSM as the security administrator (admin), and then verify the DSM configuration has been restored correctly.