CHAPTER 3 HSM Initialization
Initializing a Password-Authenticated HSM
In this section, you initialize the HSM portion of the Luna appliance, and set any policies that you require. In normal
operation, you would perform these actions just once, when first commissioning your Luna appliance.
Note:
Perform initialization only after you have set the system-level parameters (time, date,
timezone, use of NTP (Network Time Protocol), etc.) , and configured network and IP settings
to work with your network.
Initialization prepares the HSM for use by setting up the necessary identities, ownership and authentication that are to
be associated with the HSM. You must initialize an HSM one time before you can generate or store objects, allow
clients to connect, or perform cryptographic operations.
Once you have initialized an HSM, you would return to this section only to clear an entire HSM and all its contents and
HSM Partitions, by re-initializing.
"Initializing a Password Authenticated HSM" on page 44
Initializing a Password Authenticated HSM
Initialize the HSM , to set up the necessary identities, ownership and authentication at the HSM Server level. This is
required before you can create Partitions and use the HSM.
Start the Initialization Process
The
hsm init
command takes several options. See
"hsm init" on page 1
in the
Lunacm Command Reference
. See
"hsm init" on page 1
in the
Lunash Command Reference
.
For an HSM with Password Authentication, you need to provide a label, password, and cloning domain. The only one
that you should type at the command line is the label. The password and cloning domain can be typed at the command
line, but this makes them visible to anyone who can see the computer screen, or to anyone who later scrolls back in
your console or ssh session buffer.
If you omit the password and the domain,
lunash
prompts you for them, and hides your input with "*" characters. This
is preferable from a security standpoint. Additionally, you are prompted to re-enter each string, thus helping to ensure
that the string you type is the one you intended to type.
Label
The label is a string of up to 32 characters that identifies this HSM unit uniquely. A labeling convention that conveys
some information relating to business, departmental or network function of the individual HSM is commonly used.
HSM password
The HSM password is a password for the HSM, within the HSM appliance. For proper security, it should be different
than the appliance admin password, and it should employ standard password-security characteristics:
•
at least 8 characters,
•
not easily guessable (therefore, no words that occur in any dictionary)
•
no dates like birthdays or anniversaries, no proper names
•
should include miXEd-CAse letters, numbers, special (non-alphanumeric, -_!@#$%&*...).
Luna SA Configuration Guide
Release 5.4.1 007-011136-007 Rev C July 2014 Copyright 2014 SafeNet, Inc. All rights reserved.
44
Содержание Luna SA
Страница 1: ...Luna SA Configuration Guide ...