CHAPTER 3 HSM Initialization
Cloning domain
The cloning domain is a shared identifier that makes cloning possible among a group of HSMs. Cloning is required for
backup or for HA. Cloning cannot take place between HSMs that do not share a common domain.
A domain is created (new) or is imprinted (from an existing domain) when you initialize the HSM.)
Initialize a Password Authenticated HSM
Type the
hsm init
command at the lunash prompt, supplying a text label for the new HSM.
lunash:> hsm -init -label myLuna
> Please enter a password for the security officer
> ********
Please re-enter password to confirm:
> ********
Please enter the cloning domain to use for initializing this
HSM (press <enter> to use the default domain):
> ********
Please re-enter domain to confirm:
> ********
CAUTION: Are you sure you wish to re-initialize this HSM?
All partitions and data will be erased.
Type 'proceed' to initialize the HSM, or 'quit'
to quit now.
>proceed
‘hsm - init’ successful.
When activity is complete, lunash displays a “success” message.
You have initialized the HSM and created an HSM Admin identity, which is an additional capability set, overlaid on the
HSM appliance administrator identity.
•
Appliance “admin” alone can use lunash to perform some administrator operations on the HSM server, such as
network configuration, but cannot access the HSM without additional authentication
•
HSM Admin (equivalent to the Cryptoki “Security Officer” or “SO”) can administer the HSM, but requires that the
system “admin” be logged in first (same ssh session), before HSM Admin can login.
In order to perform all possible administrative functions on the HSM appliance, you must have both the “admin”
password for lunash and the HSM Admin authentication.
You are ready to adjust HSM Policies (if desired) and begin creating HSM Partitions for your Client's applications to
use.
"Set HSM Policies (Password Authentication)" on page 67
Luna SA Configuration Guide
Release 5.4.1 007-011136-007 Rev C July 2014 Copyright 2014 SafeNet, Inc. All rights reserved.
45
Содержание Luna SA
Страница 1: ...Luna SA Configuration Guide ...