CHAPTER 6 Partition Policies
CHAPTER 6
Partition Policies
At this point, you should have initialized the HSM and created an HSM Partition. You may need to set the policies that
constrain the use of the HSM Partition by clients. Capabilities are factory settings ( ). Policies are the means of
modifying the adjustable capabilities.
First, display the policies (default) of the created HSM Partition.
In order to run the
partition showPolicies
command, you do not need to be logged into the HSM Partition.
However, to change policies of either the HSM or an individual Partition, you must login as HSM Administrator.
1.
View the Partition policies. At the lunash prompt, type the command
lunash:> partition showPolicies -partition mypartition
Partition Name: mypartition
Partition Num: 65038002
The following capabilities describe this partition and can
never be changed.
Description
Value
===========
=====
Enable private key cloning
Allowed
Enable private key wrapping
Disallowed
Enable private key unwrapping
Allowed
Enable private key masking
Disallowed
Enable secret key cloning
Allowed
Enable secret key wrapping
Allowed
Enable secret key unwrapping
Allowed
Enable secret key masking
Disallowed
Enable multipurpose keys
Allowed
Enable changing key attributes
Allowed
Enable PED use without challenge
Allowed
Allow failed challenge responses
Allowed
Enable operation without RSA blinding
Allowed
Enable signing with non-local keys
Allowed
Enable raw RSA operations
Allowed
Max failed user logins allowed
10
Enable high availability recovery
Allowed
Enable activation
Allowed
Enable auto-activation
Allowed
Minimum pin length (inverted: 255 - min) 248
Maximum pin length
255
Enable Key Management Functions
Allowed
Enable RSA signing without confirmation
Allowed
Enable Remote Authentication
Allowed
Enable private key unmasking
Allowed
Enable secret key unmasking
Allowed
Enable RSA PKCS mechanism
Allowed
Luna SA Configuration Guide
Release 5.4.1 007-011136-007 Rev C July 2014 Copyright 2014 SafeNet, Inc. All rights reserved.
88
Содержание Luna SA
Страница 1: ...Luna SA Configuration Guide ...