Backup of sensitive data (Overview)
  • 26 Nov 2024
  • 1 Minute à lire
  • Sombre
    Lumière
  • PDF

Backup of sensitive data (Overview)

  • Sombre
    Lumière
  • PDF

The content is currently unavailable in French. You are viewing the default English version.
Résumé de l’article

We strongly recommend to back up the following security-sensitive data:

  • Configuration files
  • SSL/TLS certificates and private keys
  • Host files (such as DIGIPASS export file (DPX), PIN, PUK)
  • Audit log data
  • Audit report information
  • Authenticator BLOB data

Configuration files

The configuration files for OneSpan Authentication Server, Message Delivery Component, and the Tcl Command-Line Administration tool can be copied from the following folder:

/etc/vasco/ias (Linux)

%PROGRAMFILES%\VASCO\IDENTIKEY Authentication Server\bin (Windows)

The files to be copied are:

  • identikeyconfig.xml. For all instances of OneSpan Authentication Server.
  • mdcconfig.xml. A backup copy of one working file is sufficient.
  • dpadmincmd.xml

Save the aforementioned files with an extension that describes the server from which the file(s) were backed up. This makes it easier and quicker to locate the correct file during recovery.

Database encryption certificates and keys

If you are using database encryption, you should back up all certificates and private keys used.

If you have enabled database encryption for the embedded MariaDB database, you need to back up the following files:

  • cert/ca-cert.pem
  • cert/ca-key.pem
  • cert/client-cert.pem
  • cert/client-key.pem
  • cert/server-cert.pem
  • cert/server-key.pem
  • encr/dbkeys.enc

The cert and encr subfolders are usually located in the program data folder:

  • %PROGRAMDATA%\VASCO\IDENTIKEY (Windows)
  • /etc/vasco/ias (Linux)

SSL/TLS certificates and private keys

Any SSL/TLS certificates and private keys used with OneSpan Authentication Server should be backed up.

For more information about SSL certificates generated by the Maintenance Wizard, refer to the OneSpan Authentication Server Administrator Guide.

Host files

The DIGIPASS export file (DPX) is provided on secure media, which can be stored securely as a backup. If you prefer another method for archiving, copy the files to your preferred location. It is important to keep the DPX file transport keys secure and preferably in a separate location from the DPX files.

For more information about protecting host files, see Protecting host files.

Audit log data and data store

For more information, see Audit log data backup and Data store backup: Strategies.


Cet article vous a-t-il été utile ?

Changing your password will log you out immediately. Use the new password to log back in.
First name must have atleast 2 characters. Numbers and special characters are not allowed.
Last name must have atleast 1 characters. Numbers and special characters are not allowed.
Enter a valid email
Enter a valid password
Your profile has been successfully updated.
ESC

Ozzy, facilitant la découverte de connaissances grâce à l’intelligence conversationnelle