Chapter 2: Client Connections
>
Add your SSH key (lunash:>my public-key add …)
Here is an example session:
operator@mypc:~/.ssh$ scp id_rsa.pub op-number1@lunasa6:
op-number1@lunasa7's password:
id_rsa.pub
100%
392
0.4KB/s
00:00
operator@mypc:~$ ssh op-number1@lunasa7
op-number1@lunasa7's password:
Last login: Wed Mar
11 08:51:46 2015 from 192.168.10.18
SafeNet Luna Network HSM 7.0 Command Line Shell - Copyright (c) 2001-2017 Gemalto, Inc. All rights
reserved.
[lunasa7] lunash:>my publickey add id_rsa.pub
Command Result : 0 (Success)
When to Restart NTLS
Here are the situations where NTLS needs restarting.
NOTE
All client connections must be stopped before you restart NTLS.
>
When you regenerate the server certificate (the interface prompts you to restart NTLS after regenerating
the server cert)
>
If you delete Partitions
>
If you change binding settings (with
ntls bind
)
In all other circumstances, NTLS should remain running. If there are problems with clients connecting to the
SafeNet appliance, other methods of debugging should be attempted before restarting NTLS.
Examples are:
>
Confirming the fingerprint of the client certificate and the server certificate at both the client and the server
(the SafeNet appliance).
>
Verifying that the client is registered and has at least one Partition assigned to it.
Impact of the service restart ntls Command
If you perform a
service restart ntls
on a live, or production SafeNet appliance, any active sessions would be
lost. That is, HSM Partitions would remain active, but Clients would need to re-connect and re-authenticate.
As a general rule, an NTLS restart is required immediately after a server certificate regeneration on a SafeNet
appliance. This occurs under the following circumstances only:
>
As part of original installation and setup.
>
If you have reason to suspect that the SafeNet appliance's server certificate (private key) has been
compromised.
In the former case, there is no impact. In the latter case, the brief disruption of active Clients would be
overshadowed by the seriousness of the compromise.
SafeNet Luna Network HSM 7.3 Appliance Administration Guide
007-013576-005 Rev. A 13 December 2019 Copyright 2001-2019 Thales
38