SafeNet ProtectServer External 2 Скачать руководство пользователя страница 17

 

11 

9.  Verify that you have SSH network access to the PSe (if required) 

Refer to "SSH network access" on page 13 for details 

10. Detach keyboard and monitor if no longer required (if applicable) 

System testing 

Before field test and deployment we recommend that you run the diagnostic utility 

hsmstate

 to ensure that the unit is functioning correctly. To do this type 

hsmstate 

at a 

command line prompt. 

If the unit is functioning correctly a message that includes the following is returned: 

NORMAL MODE. RESPONDING. 

You can also use the 

PSE_status

 command to verify that the PSE2 is functioning 

correctly, as described below.

 

The PSE_status command 

Syntax 

PSE_status

 

Description 

This utility displays the current status of the Protect Server External 2 (PSE2). It 
provides the following information: 

 

the status of the HSM installed in the PSE2. If the unit is functioning correctly, a 
message that includes the following is returned: 

PSE status NORMAL 

 

the status and process ID (pid) of the 

etnetserver

 process. 

Example 

[admin@PSe ~] PSE_status

 

1) HSM device 0:      HSM in NORMAL MODE. 

2) etnetserver (pid 1026) is running... 

PSE status NORMAL 

Setting the IP address 

The PSE2 is equipped with two NICs (

eth0

 and 

eth1

), each of which can be 

configured with its own IP address. The IP address for each NIC is specified in the 
following files: 
 

NIC 

Configuration file 

eth0 

/etc/sysconfig/network-scripts/ifcfg-eth0 

eth1 

/etc/sysconfig/network-scripts/ifcfg-eth1 

Note:

 If you want to use the 

eth1

 interface, you must 

create this file. The recommended method is to copy, 
rename, and edit the 

ifcfg-eth0

 file. 

Содержание ProtectServer External 2

Страница 1: ...i ProtectServer External 2 PSE2 Installation Guide...

Страница 2: ...FCC compliance only devices also known to comply should be connected to the adapter s serial ports If such devices do not feature their own cables shielded cables must be used Disclaimer SafeNet make...

Страница 3: ...United States 800 545 6608 Web www safenet inc com Support and Down loads www safenet inc com support Provides access to the SafeNet Knowledge Base and quick downloads for various products Technical...

Страница 4: ...allation procedure 7 To install the hardware 7 Smart Card Reader Installation 7 Chapter 5 Testing and configuration 9 Equipment requirements 9 Procedure overview 9 System testing 11 The PSE_status com...

Страница 5: ......

Страница 6: ......

Страница 7: ...ps are given References to further documentation are cited where needed Chapter 4 describes the installation procedure Chapter 5 deals with testing and network setting configuration A troubleshooting...

Страница 8: ...services include encryption decryption signature generation and verification and key management with a tamper resistant and battery backed key storage To implement a cryptographic service provider use...

Страница 9: ...liance using the included USB to serial cable HSM serial port pin configuration The serial port on the USB to serial cable uses a standard RS232 male DB9 pinout as illustrated in Figure 2 Figure 2 HSM...

Страница 10: ...o destroy any keys currently stored on the HSM When the key is in the horizontal Active position the HSM is in normal operating mode When the key is in the vertical Tamper position the HSM is in the t...

Страница 11: ...ted using a standalone SafeNet Protect Server External 2 PSE2 HSM the cryptographic service provider will operate in network mode In network mode Network HSM Access Provider software is installed on t...

Страница 12: ...nd configured to support operation in network mode Full details are in the Hardware Security Module Access Provider Install Configuration Guide supplied with the software 5 Install the high level cryp...

Страница 13: ...ic API software is installed Connect the PSE2 to the network by inserting standard Ethernet cables into the LAN connectors located on the front of the PSE2 The LAN connectors are autosensing 10 100 10...

Страница 14: ...r crypto server for security reasons then connect a PS 2 to USB adapter cable between the card reader and a standalone powered USB hub Again the USB connection is for power only No data transfer occur...

Страница 15: ...he RJ45 console port to a terminal emulation device such as a laptop or terminal server Note If you want to access the PSE2 console remotely using the console port you will need a cable If your termin...

Страница 16: ...as admin only The default passwords for the root and admin users are as follows User name Default password root password admin password At this time we strongly recommend that you use the passwd comm...

Страница 17: ...y displays the current status of the Protect Server External 2 PSE2 It provides the following information the status of the HSM installed in the PSE2 If the unit is functioning correctly a message tha...

Страница 18: ...ces to operate as their own name servers If name resolution is required it needs to be provided by a DNS server on the network In order for the PSE2 to use the DNS server you must add an entry for the...

Страница 19: ...bles stop etc init d iptables start SSH network access After you have completed the network configuration you can access the PSE2 over the network using the SSH protocol To access the PSE2 using SSH y...

Страница 20: ...tories listed above usbflash cdrecorder are just examples The name can vary depending on the device capability and how it is detected Troubleshooting Each Protect Server External 2 is tested during ma...

Страница 21: ...isk DOM 10 100 1000 Mbps autosensing Network Interface with RJ45 LAN connector Pre installed Software Linux operating system SafeNet PCI HSM Access Provider software SafeNet HSM Net Server software Po...

Страница 22: ...END OF DOCUMENT...

Отзывы: