CHAPTER 3 HSM Initialization
"Fresh" PED Keys
Pre-used PED Keys
(reuse)
Pre-used PED Keys (overwrite)
The PED prompts in similar fashion to
the steps for the HSM Admin/SO key
above (overwrite, copy, etc.).
If asked to "Reuse Id", the best option
is to say "YES", unless you have
good reason to create a new domain
not shared with any previous HSM
.
Here, your response to "Reuse ID?"
might or might not be the same as you
chose for the blue key, above. You
might have good reason to make this
HSM part of an existing Domain
.
Here, your response to "Reuse
ID?" might or might not be the
same as you chose for the blue
key, above. You might have good
reason to make this HSM part of
an existing Domain.
HSM Init process is finished.
HSM Init process is finished.
HSM Init process is finished
.
Table 1: PED prompt sequences
Some additional comments about some of the choices:
Provide a PED PIN (optional)
A PED PIN can be 4-to-16 digits, or can be no digits if a PED PIN is not desired .
Enter a PIN if you wish, and press [Enter] to inform Luna PED that you are finished entering PED PIN digits, or that you
have decided not to use a PED PIN (no digits entered).
Confirm, by entering the same PIN (or nothing if you did not enter a PIN the first time), and pressing [Enter] again.
(When you provide a PED PIN – even if it is the null PIN (by just pressing [Enter] with no digits) – Luna PED asks for it
a second time, to ensure that you entered it correctly.)
In future, every time you are required to present that PED Key, you must also enter the PED PIN on the PED keypad - if
you created a PED PIN at initialization time, then you must provide that exact PED PIN along with the PED Key, in
order to gain access to the HSM. If you did not create a PED PIN when you initialized, then just press [Enter] at the
PED prompt when you insert the requested PED Key during login.
When you are attempting to log in, the PED always asks for a PED PIN, regardless whether or not a real PED PIN is
expected. That's a security feature, similar to password-protected systems that tell you if you have entered incorrect
credentials, but don't specify if it was the login name or the password that was individually the faulty part.
Duplicating Your PED Key
“Are you duplicating this keyset? (Y/N)”
If you respond “NO”, Luna PED imprints just the one blue HSM Admin key (or Domain key (see below) and goes on to
the next step in initialization of the HSM.
If you respond “YES”, Luna PED imprints the first blue key and then asks for more blue PED Keys, until you have
imprinted (duplicated) as many as you require.
Note:
It is recommended to have at least one full backup set of imprinted PED Keys, stored in
a safe place, in case of loss or damage to the primary keys. Of course, a backup set does not
need to be stored in one location. Your security protocols might require that individual backup
PED Keys be stored at separate locations according to role.
Luna SA Configuration Guide
Release 5.4.1 007-011136-007 Rev C July 2014 Copyright 2014 SafeNet, Inc. All rights reserved.
65
Содержание Luna SA
Страница 1: ...Luna SA Configuration Guide ...