If you want to move a CSP Vault node to a different server, you can simply remove the old server and then install the Cryptographic Security Platform Vault software on the new server and join the new server to the cluster so that the object store is copied to the new server and all your configuration settings are retained. As long as one node remains in the cluster, you can change the other servers out as needed.

Note: If you want to move a Cryptographic Security Platform Vault node in a single-node system, see Moving a CSP Vault Node to a New Server in a Single Node Environment.

Procedure 

  1. Log into the Cryptographic Security Platform Vault Management webGUI on any node you are not moving using an account with Domain Admin privileges.
  2. In the top menu bar, click Cluster.
  3. Click the Servers tab.
  4. Select the Cryptographic Security Platform Vault node that you want to move and select Actions > Remove.
  5. Log into the existing server as htadmin.

    Cryptographic Security Platform Vault displays the Entrust Cryptographic Security Platform Vault System Console TUI (Text-based User Interface).

  6. Select Shutdown System from the Entrust Cryptographic Security Platform Vault System Console.
  7. Optionally, uninstall Cryptographic Security Platform Vault as described in Decommissioning a CSP Vault Node.
  8. Decommission or re-purpose the server as needed.
  9. Set up the new hardware and install Cryptographic Security Platform Vault as an additional node in an existing cluster. For details, see CSP Vault ISO Installation for Hypervisors or CSP Vault OVA Installation.

    If possible, make sure the new system uses the same IP address as the old system so that all Policy Agents can find the new systems. If you need to change the system IP address, you need to update the appropriate Cluster Node Mappings or update the list of authorized IP addresses with each Policy Agent as described in Changing a Cluster Node Mapping and Updating CSP Vault Node IP Addresses on an Individual VM.