CHAPTER 5 Creating a Partition on the HSM
It is not obvious from this entry what the serial number is for the created partition. This information, however, can be
derived from the log entry, since the partition serial number is simply a concatenation of the HSM serial number and the
partition container number, which are specified in the log entry, as highlighted below:
5,12/12/17 16:14:14,S/N
150718
session 1 Access 2147483651:2669 SO container operation LUNA_
CREATE_CONTAINER returned RC_OK(0x00000000) container=
20
(using PIN (entry=LUNA_ENTRY_DATA_
AREA))
In the example above, the HSM serial number is 150718 and the partition container number is 20. Note that the partition
container number is a three-digit number with leading zeros suppressed, so that the actual partition container number is
020. To determine the partition serial number concatenate the two numbers as follows:
150718020
Use this number to identify the partition in subsequent audit log entiries.
Record the Partition Client Password (PED-Auth HSMs)
The PED now generates and displays the Client Password (login secret), by which Clients will later authenticate
themselves to this HSM Partition.
Record the Login Secret Value from the PED screen – write it down legibly – because it will never be shown again. This
is the HSM Partition password, used to authenticate Client applications that wish to use the HSM Partition on the Luna
SA.
Note:
It might be best to use a text editor, because the majority of errors tend to occur when
reading hand-written values. The password/challenge secret is case-sensitive.
Note:
The PED times out after eight minutes. You must complete recording the password and
press the ENTER button before time-out occurs.
Luna SA Configuration Guide
Release 5.4.1 007-011136-007 Rev C July 2014 Copyright 2014 SafeNet, Inc. All rights reserved.
85
Содержание Luna SA
Страница 1: ...Luna SA Configuration Guide ...