intermediate network(s). Always verify that the received certificate matches the expected value (HSM SN, date
generated, etc.). This configuration prevents Man-in-the-Middle and other malicious attacks. If possible,
connect the HSM directly to the client using a cross-cable.
The ProtectServer 3 External includes two network ports, each of which can be connected to a different
network. It is highly recommended that you keep the management network and the network running your
applications isolated from each other at all times. Further restrictions on communication between network
segments can be enforced by means of static routes. See
"Network Configuration" on page 27
for instructions
on setting up static routes.
The ProtectServer 3 External supports an iptables-based firewall. The firewall must be configured with
appropriate rules to restrict access to identified network resources only. See
for details on setting iptables.
Separation of Roles
The ProtectServer 3 External has two role categories: Appliance and HSM users. For optimal security,
maintain these roles and their credentials separately; do not share between users. Do not share the appliance
management, HSM Administration, and User terminals.
Appliance Users
The following roles can log in to the PSE shell (PSESH) to configure and manage the appliance:
>
admin
>
pseoperator
>
audit
See
in the
PSESH Command Reference Guide
for the responsibilities of each role.
HSM Users
The following roles can log in to manage the HSM token and perform cryptographic operations:
>
Administration Security Officer (ASO)
>
Administrator
>
Security Officer (SO)
>
Token Owner (User)
See
in the
ProtectToolkit-C Administration Guide
for the responsibilities of each role.
First Login and System Test
When starting up your ProtectServer 3+ External for the first time, follow these steps:
>
"Access the Console, Power On, and Log In" on the next page
>
Thales ProtectServer 3 HSM and ProtectToolkit 7 Installation and Configuration Guide
2021-06-30 10:29:48-04:00 Copyright 2009-2021 Thales Group
25