Restoring Repositories and Recovering from Disasters
You must review the following steps when restoring, moving, or rebuilding a DRM environment that uses installation and configuration files such as entropy file.
To Restore Repositories, perform the following steps:
-
Install or restore DRM on the target host.
Use the same DRM release or the target release you plan to run. In the EPM update workflows, the product is installed first and then configured on the target machine.
-
Stop DRM services before you restore files.
Stop all DRM-related services so the database and configuration files are not in use during recovery. However, even for the update workflow, you must require stopping all the DRM services before applying changes.
-
Restore the DRM repository database.
Restore the repository backup to the same host or to the replacement host, depending on the scenario.
-
Restore the matching DRM configuration files.
Bring back the configuration files from the same environment backup as the repository database.
-
Restore the matching configuration file, if available.
Restore the
drm-dpapi-entropy.keyfile if it exists in the backup. -
Verify file permissions.
Make sure the DRM service identities can read the restored files.
-
Start the DRM services.
The startup workflow is to start the product services after configuration and restoration.
NOTE: The services can be started with the standard startup scripts or a single start script.
-
Re-enter or reset any protected values that cannot be decrypted.
If the original key or entropy files are missing, re-enter affected passwords, connection strings, or other protected settings through supported DRM screens or tools.
-
Verify the restored environment.
Confirm that the following works:
-
Repository or Database connection
-
EPM or CSS configuration
-
SMTP configuration
-
Imports and Exports that use stored credentials
-
Scheduled jobs and Integrations
Note:
It is highly recommended to check the deployment after startup and update tasks are complete.
-
Common Restore Scenarios
The following table summarizes recommended recovery procedures:
Table 18-2 Multiple Use Cases for Restoring DRM Environments
| Restoring Scenarios | Recommended Actions | Expected Outcomes |
|---|---|---|
| Restore repository on the same host |
Restore repository, DRM configuration, and matching
|
Host restored. |
| Restore repository on a replacement host |
Restore repository and matching configuration or
|
Host replaced. |
| Move DRM to a new server |
Copy repository and matching configuration or
|
DRM migrated. |
| Rebuild a DRM server after failure |
Restore the complete DRM environment, including configuration and
|
DRM rebuilt. |
| Refresh a test or development environment from production |
Restore repository and matching configuration or
|
Environment refreshed. |
Troubleshooting Tips
What Happens When Encryption Files are Missing?
If the restored repository does not match the available configuration file, DRM may experience one or more of the following issues:
-
Protected value decryption errors
-
Failed EPM/CSS authentication
-
Failed SMTP authentication
-
Repository connection failures
-
DRM service startup failures if required protected values cannot be decrypted
Recovering from Decryption Failures
If DRM cannot decrypt protected values:
-
Determine whether the matching configuration file from the original installation is available.
-
If available, restore the matching
drm-dpapi-entropy.keyfile.-
Verify that the DRM service account has permission to read it.
-
Restart the DRM services.
-
-
If the original files are unavailable:
Re-enter or reset the affected passwords and connection strings using the supported DRM configuration screens or tools.
-
NOTE: Do not manually modify encrypted values stored in the DRM repository database. If needed, you can contact My Oracle Support