[Opendnssec-user] Questions about SoftHSM and 'ods-ksmutil backup'

Rickard Bellgrim rickard at opendnssec.org
Fri Sep 25 06:02:38 UTC 2015


On Thu, Sep 24, 2015 at 4:55 PM, Rick van Rein <rick at openfortress.nl> wrote:

>
> The SQLite backups are made at the database level, and that is the level
> at which you should look for tooling support for import / recover the
> backup.  The default procedure in lieu of any would be to stop KASP,
> replace the database with the newly copied backup, and bring the KASP
> backup.
>

Also, there are no keys in the KASP database, only the metadata about them.
The keys are stored in the HSM. In SoftHSM, the keys are stored in the
token database according to softhsm.conf. The README have more information
on the backup procedures.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.opendnssec.org/pipermail/opendnssec-user/attachments/20150925/abb8c3b0/attachment.htm>


More information about the Opendnssec-user mailing list