PAM 3.0.1 and later.
The primary purpose of database and configuration backups is to be able to go back to a known good state if a PAM database gets corrupted due to internal or user errors. But it is still possible to prepare a disaster recovery (DR) site because the key external to the database is shared by all nodes of a cluster. The new recommended procedure for setting up a DR environment is as follows:
- Make a temporary configuration change of your cluster (or create a cluster configuration if you have a single PAM node) in production and add one node in the DR site where you may want/need to restore a DB backup at some later time.
- Start the cluster. This will copy the key to the DR node.
- Stop the cluster, remove the DR node from the cluster configuration and start the cluster. Production now is decoupled from the DR site again.
- On the DR node replace the cluster configuration from the production node with the correct configuration for the DR site.
- Now you can turn your DR node off.
- At a future time, when there is need for DR, bring up your DR instance and load the latest database backup from production. This will work because the DR node has the correct key.