Oracle® Key Manager 3 Disaster Recovery Reference Guide Release 3.0 E49726-01 |
|
![]() Previous |
![]() Next |
OKM uses a Cluster design that requires at least two KMAsFoot 1 . This design helps reduce the risk of disrupting business continuity.
In addition, some design and safe-guard requirements are in place to assist in component recovery.
Clustering KMAs allows for replication of database entries and workload balancing. In the unlikely event that a component should fail, it can be easily replaced and restored to operation.
While designing an encryption and archive strategy, an important design guideline is to make sure that critical data generated at any site is replicated and vaulted off-site. This is described in Chapter 3, "Data Recovery".
This chapter provides information about replacing components in the OKM.
A single KMA can be recovered without any impact to the rest of the Cluster as long as at least one KMA remains operational. The following sections address scenarios that require recovery of a single KMA.
Software upgrades do not imply a repair or a recovery; however, sometime during this action a KMA will be out of service as the upgrade takes place.
An upgrade can be done without interrupting the active encryption agents.
Downloading the new software can be done concurrently on all KMAs in the Cluster.
Activating of the new software requires a reboot of the KMA server.
Therefore, rebooting the KMAs in the Cluster must be staggered so that at least one KMA is active at all times.
As each KMA returns to an online status, any database updates done while the KMA was offline are replicated and all KMAs in the Cluster are re-synchronized.
When a KMA is disconnected from the management network, such as when new software is activated, the remaining KMAs in the Cluster continue to attempt to contact it and report communication errors in the audit event log.
Agents continue to communicate with other KMAs across the network. Usually these are other KMAs attached to the same service network. However, because Agents may be attached to the management network, they first attempt to work with KMAs in their own configured site; but if need be, they will contact any reachable KMAs within the Cluster.
When the KMA is reconnected to the network, any database updates done while the KMA was disconnected are replicated and all KMAs in the Cluster are re-synchronized.
If a hardware failure occurs, first the KMA should be deleted from the Cluster so that the remaining KMAs will no longer attempt to communicate with it.
If the KMA console is still accessible, you can reset the KMA. The reset operation will return the unit to its factory defaults. This operation offers the option to scrub the server's hard disk as an extra security precaution. Disposition of the failed server is handled by the customer.
A replacement KMA server is configured and added to the Cluster as described in the Oracle Key Manager System Installation and Service Manual, PN E48395-01.
Once the new KMA is added to the Cluster:
The database is replicated.
The KMAs in the Cluster are re-synchronized.
The new KMA becomes an active member of the Cluster.
Table 2-1 Component Configuration
Account Name: |
|||
Security Officers: |
|||
Quorum Members: |
|||
Site Location: |
KMA S/N: |
KMA Name: |
KMA Firmware Level: |
KMA IP Address: |
Service Network IP: |
||
OKM Manager IP: |
ELOM/ILOM IP: |
||
NTP|Yes__No__IP: |
DHCP|Yes__No__ |
||
Gateway|Yes__No__IP: |
DNS|Yes__No__IP: |
||
IPv6 Yes__No__ |
Domain: |
||
Address: |
Hostname: |
||
KMA Number: |
Number of KMAs in Cluster: |
||
KMA Location: |
OKM Manager Location: |
||
Configuration Types: |
SL8500 library SL3000 library SL500 library 9310 library L700/1400 library |
Tape Drive Types: |
T10000A tape drive T10000B tape drive T10000C tape drive T10000D tape drive T9840D tape drive HP LTO tape drive IBM LTO tape drive |
Site Location: |
KMA S/N: |
KMA Name: |
KMA Firmware Level: |
KMA IP Address: |
Service Network IP: |
||
OKM Manager IP: |
ELOM/ILOM IP: |
||
NTP|Yes__No__IP: |
DHCP|Yes__No__ |
||
Gateway|Yes__No__IP: |
DNS|Yes__No__IP: |
||
IPv6 Yes__No__ |
Domain: |
||
Address: |
Hostname: |
||
KMA Number: |
Number of KMAs in Cluster: |
||
KMA Location: |
OKM Manager Location: |
||
Configuration Types: |
SL8500 library SL3000 library SL500 library 9310 library L700/1400 library |
Tape Drive Types: |
T10000A tape drive T10000B tape drive T10000C tape drive T10000D tape drive T9840D tape drive HP LTO tape drive IBM LTO tape drive |
Footnote Legend
Footnote 1: Multiple Servers: Exceptions to this standard configuration must be made with the approval of OKM Engineering and Global Support Services.