CHAPTER 4 HSM Capabilities and Policies
FIPS-validated algorithms if your application requires them.
The example listing above indicates that non-validated algorithms have been activated. The
HSM is just as safe and secure as it is with the additional algorithms switched off. The only
difference is that an auditor would not validate your configuration unless the set of available
algorithms is restricted to the approved subset.
2.
In order to change HSM policies, the HSM Administrator must first login.
lunash:> hsm login
(If you are not logged in, the above command logs you in, prompting for the HSM Admin password. If you are
already logged in, the HSM tells you so, with an error message, that you can ignore.)
3.
If you need to modify a policy setting to comply with your operational requirements, type:
lunash:> hsm changePolicy -policy <policyCode> -value <policyValue>
As an example, change code 15 from a value of 1 (On) to 0 (Off).
Example – Change of HSM Policy
lunash:> hsm changePolicy -policy 15 -value 0
That command assigns a value of zero (0) to the policy for “HSM Admin can reset partition PIN”, turning it off.
Refer to the Reference section for a description of all and their meanings.
If you have been following the instructions on this page as part of setting up a new HSM system, then the next step is to
create virtual HSMs or HSM Partitions on the HSM that you just configured.
"Prepare to Create a Partition (Password
Authenticated)" on page 72
Set HSM Policies - PED (Trusted Path) Authentication
Set any of the alterable policies that are to apply to the HSM.
Note:
Capability vs Policy Interaction
Capabilities identify the purchased features of the product and are set at time of manufacture.
Policies represent the HSM Admin’s enabling (or restriction) of those features.
1.
Type the
hsm showPolicies
command, to display the current policy set for the HSM.
lunash:> hsm showPolicies
HSM Label:
mysa5hsm
Serial #:
700022
Firmware:
6.2.1
The following capabilities describe this HSM, and cannot be altered
except via firmware or capability updates.
Description
Value
===========
=====
Enable PIN-based authentication
Disallowed
Enable PED-based authentication
A
L L O W E D
Performance level
15
Enable domestic mechanisms & key sizes
Allowed
Enable masking
Allowed
Enable cloning
Allowed
Luna SA Configuration Guide
Release 5.4.1 007-011136-007 Rev C July 2014 Copyright 2014 SafeNet, Inc. All rights reserved.
69
Содержание Luna SA
Страница 1: ...Luna SA Configuration Guide ...