Product Overview
The ProtectServer 3 External is a self-contained, security-hardened server providing hardware-based
cryptographic functionality through a TCP/IP network connection. Together with high-level SafeNet application
programming interface (API) software, it provides cryptographic services for a wide range of secure
applications.
The ProtectServer 3 External is PC-based. The enclosure is a heavy-duty steel case with common PC ports
and controls. Necessary software components come pre-installed on a Linux operating system. Network
setting configuration is required, as described in this document.
The full range of cryptographic services required by Public Key Infrastructure (PKI) users is supported by the
ProtectServer 3 External’s dedicated hardware cryptographic accelerator. These services include encryption,
decryption, signature generation and verification, and key management with a tamper resistant and battery-
backed key storage.
The ProtectServer 3 External must be used with one of SafeNet’s high-level cryptographic APIs. The following
table shows the provider types and their corresponding SafeNet APIs:
API
SafeNet Product Required
PKCS #11
ProtectToolkit-C
JCA / JCE
ProtectToolkit-J
Microsoft IIS and CA
ProtectToolkit-M
These APIs interface directly with the product’s FIPS 140-2 Level 3 certified core using high-speed hardware-
based cryptographic processing. Key storage is tamper-resistant and battery-backed.
A smart card reader, supplied with the HSM, allows for the secure loading and backup of keys.
Front panel view
The features on the front panel of the ProtectServer 3 External are illustrated below:
Figure 1: ProtectServer 3 External front panel
Ports
The front panel is equipped with the following ports:
VGA
Not active.
Console
Provides console access to the appliance. See
"First Login and System Test" on page 25
Thales ProtectServer 3 HSM and ProtectToolkit 7 Installation and Configuration Guide
2021-06-30 10:29:48-04:00 Copyright 2009-2021 Thales Group
17