CHAPTER 4 HSM Capabilities and Policies
Enable special cloning certificate
Disallowed
Enable full (non-backup) functionality
Allowed
Enable ECC mechanisms
Allowed
Enable non-FIPS algorithms
Allowed
Enable SO reset of partition PIN
Allowed
Enable network replication
Allowed
Enable Korean Algorithms
Allowed
FIPS evaluated
Disallowed
Manufacturing Token
Disallowed
Enable Remote Authentication
Allowed
Enable forcing user PIN change
Allowed
Enable portable masking key
Allowed
Enable partition groups
Disallowed
Enable Remote PED usage
Allowed
Enable external storage of MTK split
Allowed
HSM non-volatile storage space
2097152
Enable HA mode CGX
Disallowed
Enable Acceleration
Allowed
Enable unmasking
Allowed
The following policies are set due to current configuration of
this HSM and cannot be altered directly by the user.
Description
Value
===========
=====
PED-based authentication
True
Store MTK split externally
False
The following policies describe the current configuration of
this HSM and may by changed by the HSM Administrator.
Changing policies marked "destructive" will zeroize (erase
completely) the entire HSM.
Description
Value Code Destructive
===========
===== ==== ===========
Allow masking
On
6
Yes
Allow cloning
On
7
Yes
Allow non-FIPS algorithms
On
12
Yes
SO can reset partition PIN
On
15
Yes
Allow network replication
On
16
No
Allow Remote Authentication
On
20
Yes
Force user PIN change after set/reset
Off
21
No
Allow off-board storage
On
22
Yes
Allow remote PED usage
On
25
No
Allow acceleration
On
29
Yes
Allow unmasking
On
30
Yes
Command Result : 0 (Success)
[myluna] lunash:>
According to the above example, the fixed capabilities require that this HSM be protected at FIPS 140-2 level 3,
meaning that the PED and PED Keys are required for authentication, and values typed from a keyboard are ignored.
The alterable policies have numeric codes. You can alter a policy with the
hsm changePolicy
command, giving the
code for the policy that is to change, followed by the new value.
Luna SA Configuration Guide
Release 5.4.1 007-011136-007 Rev C July 2014 Copyright 2014 SafeNet, Inc. All rights reserved.
70
Содержание Luna SA
Страница 1: ...Luna SA Configuration Guide ...