Chapter 1: Appliance Hardware Functions
Disabling Decommissioning
You can disable the decommissioning feature if you have the factory-installed Capability 46: Allow Disable
Decommission and Policy 46: Disable Decommission (see
"HSM Capabilities and Policies" on page 1
). The
primary reason for disabling decommissioning is to prevent the HSM from being automatically
decommissioned due to loss of battery (see
). If decommissioning is disabled, the
SafeNet Luna Network HSM has an indefinite shelf life, as far as the battery is concerned.
To disable decommissioning
1.
Ensure that the Disable Decommissioning capability is installed on the HSM. To verify that the capability is
installed, enter the following command:
lunacm:>
hsm showpolicies
If the capability is installed, Capability 46: Allow Disable Decommission and Policy 46: Disable
Decommission are listed.
2.
Enter the following command to enable Policy 46: Disable Decommission
lunacm:>
hsm changehsmpolicy -policy 46 -value 1
When to Use the Emergency Decommission Button
The primary purpose of the decommission button is for a situation where the appliance is not responding, you
wish to send it back to Gemalto, but you need a way to permanently prevent access to material contained
within the HSM.
You might find other uses, in your organization.
What to do after decommission if the SafeNet Luna Network HSM is being returned to Gemalto
1.
Obtain a Return Material Authorization and shipping instructions from Gemalto, if you have not already
done so.
2.
Pack the appliance and ship it to Gemalto.
Serial Connections
You can use a serial connection to connect a computer directly to the SafeNet Luna Network HSM to access
the LunaSH command line.You must use a serial connection to perform your initial configuration. Once the
network parameters are established, you can switch to an SSH session over your network.
Direct administration connection via serial terminal is the method for initial configuration for the following
reasons:
>
The specific IP address, randomly assigned to your SafeNet appliance by an automated testing harness
during final factory testing, is unknown.
>
Configuring network settings via SSH, in addition to requiring the original IP address, necessarily involves
losing that connection when a new IP is set.
>
A direct serial connection is the only route to log into the "Recover" account, in case you ever lose the
appliance's admin password and need to reset. Therefore, you should verify that the connection works
before you need it - performing the appliance's network configuration is an ideal test.
SafeNet Luna Network HSM 7.3 Appliance Administration Guide
007-013576-005 Rev. A 13 December 2019 Copyright 2001-2019 Thales
28