
split onto these two iKeys. When adding an additional ASA 310-FIPS to the cluster, the CODE-
SO and the CODE-USER iKeys are used to transfer the wrap key to the HSM cards on AVG
device(s) that have been added. Once the wrap key has been transferred, all synchronization
of sensitive information within the cluster takes place transparently to the user.
No passwords are associated with the CODE-SO and CODE-USER iKeys. However, for all
operations that involves using the CODE-SO and CODE-USER iKeys, these keys are used in
addition
to the HSM-SO and HSM-USER iKeys (which in turn require the correct passwords
for successful authentication).
Caution:
If you enter the wrong password for the HSM-USER fifteen (15) times in a row, the HSM-
USER iKey will be rendered unusable. This is due to the strict security specifications placed
on the ASA 310-FIPS.
Available Operations and iKeys Required
For information about the type of iKeys required to perform a specific operation, see
Table 1:
Available Operations and iKeys Required
on page 34.
Table 1: Available Operations and iKeys Required
Type of iKey Required
Operation Performed
HSM-SO
HSM-USER
CODE-SO and CODE-
USER
Installing a new ASA 310-FIPS in
a new cluster
■
■
■
Adding an ASA 310-FIPS to an
existing cluster
■
■
■
Logging in to the HSM card
■
Splitting the wrap key onto a pair
of CODE iKeys
■
■
■
Changing the HSM-SO iKey
password
Note:
To resume normal operations
after having changed the HSM-
SO iKey password, the HSM-
USER iKey is required to re-
login to the HSM card.
■
■
Changing the HSM-USER iKey
password
■
Introducing the ASA 310-FIPS
34 User Guide
April 2013
Comments? [email protected]
Содержание 3050-VM
Страница 1: ...User Guide Avaya VPN Gateway Release 9 0 NN46120 104 Issue 04 04 April 2013 ...
Страница 4: ...4 User Guide April 2013 Comments infodev avaya com ...
Страница 12: ...12 User Guide April 2013 ...
Страница 20: ...New in this release 20 User Guide April 2013 Comments infodev avaya com ...
Страница 30: ...Introducing the VPN Gateway 30 User Guide April 2013 Comments infodev avaya com ...
Страница 36: ...Introducing the ASA 310 FIPS 36 User Guide April 2013 Comments infodev avaya com ...
Страница 74: ...Upgrading the AVG Software 74 User Guide April 2013 Comments infodev avaya com ...
Страница 86: ...Managing Users and Groups 86 User Guide April 2013 Comments infodev avaya com ...
Страница 130: ...The Command Line Interface 130 User Guide April 2013 Comments infodev avaya com ...
Страница 162: ...Supported Ciphers 162 User Guide April 2013 Comments infodev avaya com ...
Страница 212: ...Syslog Messages 212 User Guide April 2013 Comments infodev avaya com ...
Страница 242: ...Definition of Key Codes 242 User Guide April 2013 Comments infodev avaya com ...
Страница 259: ...Creating a Port Forwarder Authenticator User Guide April 2013 259 ...
Страница 265: ...This will print current statistics every 3 seconds Monitoring the Port Forwarder User Guide April 2013 265 ...
Страница 266: ...Using the Port Forwarder API 266 User Guide April 2013 Comments infodev avaya com ...
Страница 274: ...X 509 274 User Guide April 2013 Comments infodev avaya com ...