The following procedure describes how to configure a node that has been in use as either a standalone node or part of a cluster to join another existing Cryptographic Security Platform Vault cluster.

Important: This process will destroy all data on the node.

Before You Begin 

  • Make sure you know the IP address of any Cryptographic Security Platform Vault node that is already part of the cluster you want to join.
  • If the node is currently part of a different cluster, you should remove the node from the original cluster so that the original cluster does not become degraded. For details, see Removing a CSP Vault Node from a Cluster.
  • If you are re-joining a node to an existing cluster and you are using an externally signed SSL certificate for Cryptographic Security Platform Vault, make sure that you use the same hostname for the Cryptographic Security Platform Vault node that it had originally. If you change the hostname, you will need to reinstall the externally signed SSL certificate on that node.

Procedure 

  1. Log into the webGUI on the Cryptographic Security Platform Vault node you want to join with the cluster.

  2. In the top right, click the Switch to Appliance Management link.
  3. In the top menu bar, click Cluster.

  4. Select Actions > Join a Cluster.

    The Join Existing Cluster window displays.

  5. On the Get Started page, review the overview information to determine that you are ready to begin. This includes: 

    • Access to the cluster you are joining the node to. We recommend that you open the webGUI for the cluster in a different tab or browser window.
    • Permissions on both this node and the cluster node so you can download and import the required certificates and files.
    • A passphrase to use during the joining process. The passphrase must contain 12 alphanumeric characters. It cannot contain spaces or special characters. This phrase is a temporary string used to encrypt the initial communication between this node and the existing Cryptographic Security Platform Vault cluster.
    • Verifying that both this node and the cluster node are running the same Cryptographic Security Platform Vault version and build. The version number for the cluster node is on the Settings > System Upgrade page.
  6. Confirm that you understand that all existing data on this node will be deleted by typing "delete my data".
  7. Click Continue.
  8. On the Download CSR page, click Generate and Download CSR.
  9. Click Continue.
  10. Switch to one of the existing nodes in the cluster and navigate to the Cluster page.
  11. Select Actions > Add a Node.
  12. On the Add a Node window, upload the CSR that you downloaded from the new node (in .pem format) and enter a passphrase to use during the joining process.

  13. Click Save and Download Bundle to download the certificate bundle from the cluster node.

    The certificate bundle is a .zip file you must unpack. It contains both an encrypted SSL certificate in .p12 format and a CA certificate in .pem format.

  14. Click OK to close the Add a Node window.
  15. Return to the new node and click Continue.
  16. On the Node page, upload the encrypted SSL certificate and CA certificate that you downloaded from the cluster node, enter the IP address or hostname of any node in the existing cluster, and enter the passphrase that you selected.
  17. Click Join.

    During the joining process, a status page is displayed on the new node. Do not refresh the browser while this is in process.

    The cluster will automatically be placed in maintenance mode.

    The node will restart after the join is complete.

  18. When the node has successfully restarted, click Login.

What to Do Next 

If necessary, update the list of Cryptographic Security Platform Vault IP addresses on the VMs associated with this cluster. If you are maintaining the list of IP addresses on the VMs, see Updating Cryptographic Security Platform Vault Node IP Addresses on an Individual VM. If you are using Cluster Node Mappings, see Changing a Cluster Node Mapping.

If you are using an HSM, see the appropriate link to rejoin the cluster: