Product Documentation

There are two types of restorations you may need to perform—a full HSM restoration and an incremental database restoration. The full HSM restoration will clear the HSM, restore the firmware, reload an MBK from backups, and restore encrypted databases to the HSM. The incremental database restoration will load any new keys and administrators from an encrypted backup.

If you are working with a new HSM that hasn't been initialized before, then you should complete Clearing the HSM and then return to complete this section.

Working from a clean HSM, there are two primary steps to restore an HSM to production readiness:

  1. The first step is to load the MBK on the HSM from MBK Smart Card backups
  2. After the MBK is loaded, then encrypted database backups can be loaded into the HSM