Cryptographic Security Platform Vault stores the configuration information, keys, and objects for all Cryptographic Security Platform Vault nodes in an encrypted object store that is shared among all nodes. Any changes you make on any Cryptographic Security Platform Vault node in the cluster is automatically disseminated to the other nodes in the cluster in a secure manner. This also allows you to backup all required information from any node in the cluster.

Important: Because encryption keys are stored in the Cryptographic Security Platform Vault backup file, you should create a new backup file every time you encrypt a new disk or rekey existing disks. If you restore Cryptographic Security Platform Vault from a backup file made before the disks were encrypted or rekeyed, the new keys will be lost and you will not be able to access the encrypted data.

You can back up Cryptographic Security Platform Vault using:

  • The Cryptographic Security Platform Vault webGUI. The encrypted backup files Cryptographic Security Platform Vault creates can be downloaded locally or accessed through NFS on authorized servers. For details, see Backing Up CSP Vault Through the webGUI.
  • A third-party application that can take and restore system snapshots. You can restore Cryptographic Security Platform Vault at any time from a previous snapshot, but if any part of the VM changes you may be required to recover the Admin key as described in Recovering Access to CSP Vault.

Note: If the cluster is degraded, you cannot perform a backup.

You can restore Cryptographic Security Platform Vault from a backup file using the Cryptographic Security Platform Vault webGUI. For details, see Restoring CSP Vault Through the webGUI.

Automatic Backup Feature

Cryptographic Security Platform Vault automatically creates a backup file once every 12 hours as long as the cluster is healthy. If this is the first time the automatic backup has completed successfully since the node was first initialized or restarted, Cryptographic Security Platform Vault records this information in the audit log. It does not send an alert or email to any Cryptographic Security Platform Vault users. It also does not record any subsequent successful backups.

The automatic backup schedule may change based on the following rules:

  • If the cluster is in a degraded state, no automatic backup is attempted. The cluster must be healthy in order for Cryptographic Security Platform Vault to create a backup file.
  • If the cluster is healthy but the automatic backup fails for some reason, Cryptographic Security Platform Vault retries the backup operation every hour. The first time the automatic backup fails Cryptographic Security Platform Vault records this information in the audit log and alerts all Cryptographic Security Platform Vault accounts with Domain Admin privileges. It does not record subsequent failed backup attempts.
  • Changes to the Cryptographic Security Platform Vault configuration may trigger an automatic backup, but it is better to backup Cryptographic Security Platform Vault manually whenever you make changes to be certain that you have an up-to-date backup file available.