Download an encrypted copy of this installation and restore it on a fresh host.
The archive contains the database, CA and certificate keys, users and MFA credentials, settings, complete audit history, HTTPS identity and locally managed SoftHSM tokens.
Keep the archive and its passphrase separately. Anyone who has both can recover your CA keys and credentials. Lost backup passphrases cannot be reset.
The destination keeps its current HTTPS address and port. The backup's CA identity and other settings are restored; all old browser sessions are invalidated.
External PKCS#11 and Azure keys remain in their providers. The backup preserves their references and credentials, but the replacement host still needs access to those providers and their modules. Local managed SoftHSM token files are included. Remote publication files and system journal logs are outside the archive.