CHAPTER 3 HSM Initialization
then you will need to take these instructions slightly out of order and perform time-related
setting changes after you initialize, rather than before.
Initialization prepares the HSM for use by setting up the necessary identities, ownership and authentication that are to
be associated with the HSM. You must initialize an HSM one time before you can generate or store objects, allow
clients to connect, or perform cryptographic operations.
If you have not used Luna HSMs and PED Keys before, please read the sub-section "
Managing PED Keys
" in the
Administration Guide
, before you start initializing.
Once you have initialized an HSM, you would return to this section only to clear an entire HSM and all its contents and
HSM Partitions, by re-initializing.
Preparing to Initialize a Luna SA HSM [PED-version]
The last thing that the production workers do, before placing your Luna SA into its shipping carton, is to press the
"Decommission" button on the back of the appliance. This sets the HSM in Factory Reset mode, ensuring that when
you receive it, it does not contain left-over objects and settings from factory burn-in and final-test. Depending on the
options that you chose when ordering, your Luna SA HSM might also arrive in “Secure Transport Mode”. If the HSM is
in Factory Reset mode only, then it is ready to be initialized by you. If the HSM is also in Secure Transport Mode, then
you must run the
hsm srk transportMode recover
command
.
How do you know?
After making an SSH or serial connection, and logging on as 'admin', show the Secure Recovery State :
[myluna] lunash:>hsm srk show
Secure Recovery State flags:
===============================
External split enabled:
yes
SRK resplit required:
no
Hardware tampered:
no
Transport mode: no
Command Result : No Error
lunash:>
Show other HSM status info :
[myluna] lunash:>hsm show
Appliance Details:
==================
Software Version:
5.1.0-25
HSM Details:
============
HSM Label:
[none]
Serial #:
700022
Firmware:
6.2.1
Hardware Model:
Luna K6
Authentication Method:
PED keys
HSM Admin login status:
Not
Logged In
HSM Admin login attempts left:
3 before HSM zeroization!
RPV Initialized:
Yes
Manually Zeroized:
No
Partitions created on HSM:
Luna SA Configuration Guide
Release 5.4.1 007-011136-007 Rev C July 2014 Copyright 2014 SafeNet, Inc. All rights reserved.
49
Содержание Luna SA
Страница 1: ...Luna SA Configuration Guide ...