![SafeNet Luna SA Скачать руководство пользователя страница 74](http://html1.mh-extra.com/html/safenet/luna-sa/luna-sa_configuration-manual_798623074.webp)
CHAPTER 5 Creating a Partition on the HSM
– avoid proper names (especially family and pets)
– avoid birthday and other easily identifiable dates.
1.
Create and name an HSM Partition. At the lunash prompt, type:
lunash:> partition create -partition myPartition1
2.
Supply the appropriate new HSM Partition password when you are prompted(that is, don't supply the password as
a command option — waiting to be prompted is generally preferable to typing the password on the command line,
because a password that is typed in response to the prompt is hidden from view by “*” characters).
NOTE: You may not set the Password to be "PASSWORD", which is reserved as the partition creation-time
default, only, and is too easy to guess for a real, operational password.
3.
Write down the HSM Partition password. This is the password that will be used:
a) to authenticate the administrator performing Partition management tasks via
lunash
b) to authenticate Client applications that wish to use the Luna HSM.
Repeat the above actions for each HSM Partition that you wish to create (to the limits of your Luna system's
configuration).
Partition creation audit log entry
Each time a partition is created, an entry is added to the audit log. Any subsequent actions logged against the partition
are identified by the partition serial number that was generated when the partition was created.
Determining the serial number of a created partition from the audit log
An audit log entry similar to the following is generated when a partition is created on the HSM:
5,12/12/17 16:14:14,S/N 150718 session 1 Access 2147483651:2669 SO container operation LUNA_
CREATE_CONTAINER returned RC_OK(0x00000000) container=20 (using PIN (entry=LUNA_ENTRY_DATA_
AREA))
It is not obvious from this entry what the serial number is for the created partition. This information, however, can be
derived from the log entry, since the partition serial number is simply a concatenation of the HSM serial number and the
partition container number, which are specified in the log entry, as highlighted below:
5,12/12/17 16:14:14,S/N
150718
session 1 Access 2147483651:2669 SO container operation LUNA_
CREATE_CONTAINER returned RC_OK(0x00000000) container=
20
(using PIN (entry=LUNA_ENTRY_DATA_
AREA))
In the example above, the HSM serial number is 150718 and the partition container number is 20. Note that the partition
container number is a three-digit number with leading zeros suppressed, so that the actual partition container number is
020. To determine the partition serial number concatenate the two numbers as follows:
150718020
Use this number to identify the partition in subsequent audit log entiries.
Next steps
If you have been following the instructions on these pages as part of setting up a new Luna appliance, then the next
step is to adjust the Partition Policy settings for the new Partition that you just configured.
You might wish to adjust
"Partition Policies" on page 88
(Optional).
Otherwise, go to
"Prepare the Client for Network Trust Link" on page 91
.
Luna SA Configuration Guide
Release 5.4.1 007-011136-007 Rev C July 2014 Copyright 2014 SafeNet, Inc. All rights reserved.
74
Содержание Luna SA
Страница 1: ...Luna SA Configuration Guide ...