Luna SA HSM
Backup your Configuration
DSM Installation and Configuration Guide
Copyright 2009 - 2020 Thales Group. All rights reserved.
105
2. Ensure that all of the partitions that will be used by a specific HA group use the same Crypto Officer password.
This is required for the HA group to function properly. See the chapter “Create Application Partitions” in the
SafeNet Luna Network HSM Configuration Guide
.
Note:
For the Crypto Officer password, only letters, numbers, and '@' '%' '_' '+' characters are
accepted .
3. Ensure that the Luna Partition Security Officer activates the partition. This is required in order for the DSM to use
the Crypto Officer password to create and access the partition. Additionally, you cannot add the Luna to the DSM
cluster without the Crypto officer password. See “Activate a PED-Authenticated Partition” in the chapter
“Configure Applications Partition” of the
SafeNet Luna Network HSM Configuration Guide
.
Note
If you change the crypto officer’s password on the Luna after the initial setup, then you must update the
partition password in the DSM using the CLI menu. See
for more information.
Backup your Configuration
Prior to attaching the Luna to the initial DSM, you
MUST
perform a complete backup of your system.
You will not have to restore the configurations for any other DSM in your cluster. When that DSM synchronizes with
the initial node, the initial node overwrites everything so that the cluster nodes are peers.
For more information, see the chapter entitled “Backing Up and Restoring” in the
DSM Administration Guide
.
Break Apart the Cluster
Before you can add a Luna to a DSM cluster, you must first break apart the Cluster so that the nodes are not
connected and function independently.
To break apart the cluster, see
"Upgrading an HA Cluster" on page 142
.
Add a Luna to the Initial Node of the HA Cluster
When you add the Luna to a DSM cluster, you must add it to the initial node of the cluster. After the Luna is setup with
the initial node, then you can add/join the remaining nodes to your DSM cluster.
Note
When adding a Luna to a DSM cluster, you must be consistent with your naming convention. If you use
the hostname of the DSM when adding the first Luna, then you must use the hostname when adding the
remaining DSMs in the cluster. Likewise, if you use the IP address for the first DSM, you must use the IP
address for the remaining DSMs.
To add the Luna to a the initial node of your DSM:
1. Log on to the CLI menu of the DSM.
2. Change to the HSM menu. At the prompt, type:
0001:DSM$ hsm
3. In the HSM menu, add the Luna, type:
0002:hsm$ luna add <LunaHostName/IP_addr>
Example
0002:hsm$ luna add 192.168.59.214