background image

 

 

 

 

 

 

 

 

 

 

SafeNet ProtectServer 
PCIe HSM  

Installation Guide 

Summary of Contents for SafeNet ProtectServer PCIe HSM

Page 1: ...SafeNet ProtectServer PCIe HSM Installation Guide ...

Page 2: ...mputer or broadcast in any media and no modification of any part of this document shall be made Use for any other purpose is expressly prohibited and may result in severe civil and criminal liabilities The information contained in this document is provided AS IS without any warranty of any kind Unless otherwise expressly agreed in writing Gemalto makes no warranty as to the value or accuracy of in...

Page 3: ...week Your level of access to this service is governed by the support plan arrangements made between Gemalto and your organization Please consult this support plan for further information about your entitlements including the hours when telephone support is available to you Contact method Contact Address Gemalto NV 4690 Millennium Drive Belcamp Maryland 21017 USA Phone Global 1 410 931 7520 Austral...

Page 4: ...Revision History Revision Date Reason A 14 March 2016 Release 5 2 ...

Page 5: ... HSM Access Provider Installation 5 Smart Card Reader Installation 5 Completing Installation 7 Chapter 3 Troubleshooting 8 Overview 8 Known Issues 8 Problem 8 Solution 8 Problem 8 Solution 8 Problem 8 Solution 9 Problem 9 Solution 9 Simple Fault Diagnosis 9 Fault Diagnosis Utilities 9 Fault Diagnosis Procedure 9 Chapter 4 Hardware Reference 10 Adapter Modification for External Tamper Detectors 10 ...

Page 6: ...THIS PAGE INTENTIONALLY LEFT BLANK ...

Page 7: ...is manual is provided as an instructional aid for the installation of a SafeNet ProtectServer cryptographic services hardware adapter Installation of the associated SafeNet ProtectServer PCIe HSM Access Provider package PTKpcihsm2 is described in the companion manual SafeNet ProtectServer HSM Access Provider Installation Guide The SafeNet PCI HSM Access Provider package includes the device driver ...

Page 8: ...THIS PAGE INTENTIONALLY LEFT BLANK ...

Page 9: ... connector suitable to mate with the tamper detect connector on the ProtectServer adapter detailed at the beginning of Appendix A 4 Install the SafeNet ProtectServer PCIe HSM card in the host computer system 5 Install the HSM Access Provider package that includes the device driver and confirm the correct operation of the adapter and driver installation 6 Use the included USB to serial cable to att...

Page 10: ...ou can use the ctconf command to test the condition of the battery If the Battery Status indication does not report as GOOD backup the HSM keys before powering down the PC to avoid losing the keys Note Disconnecting the battery deletes all key material on the HSM Ensure that you back up you HSM before disconnecting the power The keys are not deleted immediately Capacitors continue to supply power ...

Page 11: ...e consult the documentation accompanying your host system motherboard If you are using a tamper detection device route the cable to it before closing the computer cover PCI HSM Access Provider Installation After successful installation of the adapter the next steps are to 1 Install the HSM Access Provider package PTKpcihsm2 2 Confirm the correct operation of the adapter and driver package These st...

Page 12: ...ied with the ProtectServer product also requires connection to a PS 2 port for its power Many newer servers have USB ports but do not provide a PS 2 connection The options are Connect a PS 2 to USB adapter cable pink between the card reader and a USB port on the host computer If you prefer to not expose USB ports on your crypto server for security reasons then connect a PS 2 to USB adapter cable b...

Page 13: ...Provider installation to make use of the ProtectServer you will need to install the supplied SafeNet API or net server software Please refer to the installation instructions in the appropriate manual such as the SafeNet ProtectToolkit C Installation Guide ...

Page 14: ...ion or is left in an unstable state Solution This fault can occur if there are no free IRQs that can be assigned to the device Make sure the device is assigned an IRQ The IRQs assigned to devices are usually displayed when a system is powered up Problem The system locks up after installation of the HSM Access Provider device driver package This may happen if a prior version of the device driver ex...

Page 15: ...ese are installed as part of the ProtectServer PCI HSM Access Provider installation There are two utilities hsmstate and hsmreset Further information about these utilities beyond what is covered in this chapter can be found in the HSM Access Provider Installation Guide Fault Diagnosis Procedure From a command prompt execute hsmstate The output from the utility should include NORMAL mode Responding...

Page 16: ...ur tamper device s two wire cable in order to insert into the tamper detection socket on the ProtectServer adapter Crimp a pair of Molex 50212 8100 2mm WTB crimp terminals to the ends of the wires coming from your tamper switch and insert the crimped terminal sockets into the Molex connector housing Plug the connector end of the assembled cable into the tamper detect socket on the PCIe adapter In ...

Page 17: ... in a powered system The RTC performs a check of battery level daily If a low battery warning is detected on an adapter that has been un powered removed from a system then the data in the memory can be considered suspect If a low battery warning is detected on an adapter that has been continuously powered then the data in memory can be trusted for you to make a backup before proceeding with batter...

Reviews: