Chapter 1: Appliance Hardware Functions
One such event is removal of the lid (top cover). The lid is secured by anti-tamper screws, so any event that lifts
that lid is likely to be a serious intrusion.
Another event that is considered tampering is opening of the bay containing the ventilation fans.
You can use the thumbscrew to access the mesh air filter in front of the fans, without disturbing the system.
However, if you open the fan-retaining panel behind that, which requires a Torx #8 screwdriver, then the
system registers a tamper.
Therefore, cleaning of the filter is encouraged, especially if you work in a dusty environment, but fan module
removal and replacement are discouraged unless you have good reason to suspect that a fan module is faulty.
See
"Power Supply and Fan Maintenance" on page 21
for more information.
Decommission
The red "Decommission" button recessed behind the back panel is not a tamper switch. Its purpose is different.
See
"HSM Emergency Decommission Button" on page 27
for a description.
What Happens When You Tamper - Including Opening the Fan Bay
The following sequence illustrates how a tamper event affects the HSM and your use of it. You do not need to
perform all these steps. Many are included for illustrative purposes and to emphasize the state of the appliance
and of the enclosed HSM at each stage.
Action
Result/State
First, we place the HSM in its basic operational condition (we reset only to have a clean starting point for this
illustration).
hsm
factoryReset
Starting point
hsm initialize
Basic setup of HSM
Next, we illustrate a software "tamper" (destroying the MTK by setting the HSM into Transport Mode)
stm transport
Enable Secure Transport Mode.
hsm show
Basic HSM info remains undisturbed.
partition list
None have been created since initialization, above.
partition create
Attempt to create a partition - doesn't work; must be logged in as SO.
hsm login
No, can't do that either: LUNA_RET_MTK_ZEROIZED
stm recover
Log in to the HSM and HSM SO and recover from Secure Transport Mode.
Also, the PED presents the Transport Mode verification string.
SafeNet Luna Network HSM 7.3 Appliance Administration Guide
007-013576-005 Rev. A 13 December 2019 Copyright 2001-2019 Thales
16