13. Hardware Security Module
A Hardware Security Module (HSM) may be integrated with IDENTIKEY Appliance to provide an extra layer of secur-
ity to data storage.
13.1. Supported Hardware Security Modules
IDENTIKEY Appliance supports the following Hardware Security Module models:
n
SafeNet ProtectServer External 2
n
SafeNet ProtectServer Internal Express
On SUSE Linux Enterprise Server 11, only SafeNet ProtectServer Gold, SafeNet ProtectServer Orange and SafeNet
ProtectServer Internal Express are supported.
If you plan to integrate IDENTIKEY Appliance with a supported Hardware Security Module, this HSM must be
installed and functioning correctly prior to IDENTIKEY Appliance installation.
13.2. SafeNet HSMs
In order to set up SafeNet HSMs to work with IDENTIKEY Appliance, you need to set up the following components:
Software
The following software must be installed on the HSM:
n
Version 2.07 or higher of the SafeNet ProtectServer firmware
Administrator Account
The setup process requires administration privileges in at least one administration token and one user token
on the Hardware Security Module.
Functionality Module (FM)
Setting up a SafeNet HSM involves copying the VACMAN Controller functionality module file –
aal2sdk
– to the
machine which will be used for HSM administration. The VACMAN Controller functionality module file may be
unsigned or signed, depending on your requirements ().
13.2.1. Limitations in the usage of HSMs
n
IDENTIKEY Appliance only supports network Hardware Security Modules.
13. Hardware Security Module
IDENTIKEY Appliance 3.11.12 - Installation and Maintenance Guide
75