Chapter 3: DSM V6000 Hardware Appliance
nShield Connect Integration
DSM Installation and Configuration Guide
Copyright 2009 - 2020 Thales Group. All rights reserved.
65
Configure nShield Connect appliance and associated RFS
Refer to the nShield Connect documentation to set up your nShield Connect appliance and the associated RFS.
Add DSM as an nShield Connect client
Before the DSM initial node is configured to use an nShield Connect HSM, it must first be added as a client to the
nShield Connect HSM. The DSM node must be enrolled as a privileged client that does not require nToken
authentication.
Refer to the nShield Connect user documentation for detailed procedures about how to enroll a privileged client.
Add the nShield Connect HSM to the DSM
The next step is to add the nShield Connect HSM to the DSM. Open a CLI session on the DSM appliance that is a
client of the nShield Connect HSM
Note
If the nShield Connect Security World is FIPS 140-2 level 3 compliant, only one card from the associated
ACS is required for this step. The card is only required for the first HSM device to be added to the DSM, it
is not required for any subsequent nShield Connect HSMs that are added.
1. Navigate to the HSM category of commands, type the following at the prompt:
0000:dsm$ hsm
0001:hsm$
2. Use the connect add command to add the nShield Connect HSM to the DSM. Type the following command at the
prompt,
0001:hsm$ connect add <nShield_Connect_IP_Address> <RFS_IP_Address>
where,
<
nShield_Connect_IP_Address
>
is the IP address of the nShield Connect HSM and
<
RFS_IP_Address
>
is the IP address of the computer that has the RFS installed.
For example,
0001: hsm$ connect add 1.2.3.18 1.2.3.4
3. A warning displays, informing you that once this DSM is converted to a network HSM-enabled appliance, it
cannot be rolled back. Type ‘yes’ to continue.
The DSM is restarted if the operation is successful.
4. Follow the prompts to add the nShield Connect HSM to the DSM.
5. To view the nShield Connect HSM that has been added run the
connect show
command.
6. If there are more nShield HSMs in the same Security World you can add them now using the connect add
command.
7. The About page of the DSM Web UI also displays the nShield Connect HSMs that have been configured.