{% extends "base.html" %} {% block content %}
Installation recovery

Backup and recovery

Download an encrypted copy of this installation and restore it on a fresh host.

Create an encrypted backup

The archive contains the database, CA and certificate keys, users and MFA credentials, settings, complete audit history, HTTPS identity and locally managed SoftHSM tokens.

Keep the archive and its passphrase separately. Anyone who has both can recover your CA keys and credentials. Lost backup passphrases cannot be reset.

Use a unique passphrase of at least 20 characters. Archives are limited to 128 MiB.

Wait for a new code if you just used the current one to sign in.

Restore on a fresh host

  1. Install PKIMaster on the replacement host. Connect through localhost or an SSH tunnel.
  2. Choose Restore an existing installation on the initial setup page before creating an administrator.
  3. Stop the original installation, then upload the archive and enter its passphrase.
  4. The packaged HTTPS service restarts automatically. Sign in with a restored account and authenticator, then check publication URLs, monitoring and key providers.

The destination keeps its current HTTPS address and port. The backup's CA identity and other settings are restored; all old browser sessions are invalidated.

External PKCS#11 and Azure keys remain in their providers. The backup preserves their references and credentials, but the replacement host still needs access to those providers and their modules. Local managed SoftHSM token files are included. Remote publication files and system journal logs are outside the archive.

{% endblock %}