payShield 10K Installation and User Guide
©Thales Group
Page 433
All Rights Reserved
Export HSM Certificate's Chain of Trust (SE)
Variant
Key Block
Online
Offline
Secure
Authorization:
Not required
Command:
SE
Function:
To export the HSM certificate's chain of trust (i.e. the chain of certificates
required to authenticate the HSM's certificate, up to and including the root CA
certificate).
Authorization:
The HSM must be in the secure state to run this command.
Inputs:
•
Filename when saving to USB memory stick
Outputs:
•
Prompts, as above
•
Prompt to save to USB memory stick
•
Certificate Chain of Trust is displayed at the console, and (if requested)
saved to the USB memory stick
Errors:
•
File exists – replace?
Notes:
•
The HSM's public/private key pair must be installed (using the SG console
command) prior to using this command.
•
The exported file will automatically have the extension ".CRT".
•
A maximum certificate chain length of 6 is supported.
•
The required format for the USB memory stick is FAT32. The Operating
System used in the payShield 10K supports most types of USB memory
stick, but may not have the drivers for some of the newer types. If difficulties
are experienced when trying to read from or write to a USB device, an
alternative memory stick should be used.