Luna SA HSM
Add a Luna to the Initial Node of the HA Cluster
DSM Installation and Configuration Guide
Copyright 2009 - 2020 Thales Group. All rights reserved.
106
The following warning displays:
WARNING: Configuring HSM will restart Security Server service
Continue? (yes|no)[no]:yes
WARNING
If you have not yet backed up your DSM, do it now!
4. To proceed, type:
yes
The Luna hostname/IP address displays with a fingerprint:
Example
192.168.59.214: UZHnfG5tTURxZ8etW0VQHitywmiN5H8NgObKdF20j/M
The fingerprint above should match the RSA output of the
'sysconf fingerprint ssh' lunash command on the Luna SA
5. At the prompt, enter the Luna administrator username.
6. At the prompt, enter the Luna administrator password.
7. At the prompt, enter the Luna partition ID number for the partition you created.
8. (PED-authenticated Luna only) At the prompt, enter the crypto officer password set by the crypto officer:
9. Enter the hostname or IP address of this DSM. A warning displays:
WARNING: All Peer node and agent certificates will need to be re-signed after CA and server
certificates are regenerated!
The security server software will be restarted automatically.
10. To continue, type:
yes
.
11. Enter the host name of the initial node. If the name is already correct, hit
Enter
.
o
This Security Server host name [DSM08648.i.thales.com]:
12. Enter the following information for key and certificate generation.
o
What is the name of your organizational unit? []:
o
What is the name of your organization? []:
o
What is the name of your City or Locality? []:
o
What is the name of your State or Province? []:
o
What is your two-letter country code? [US]:
o
What is your email address? []:
o
What is the validity period of the generated certificate (from 2 to 10 years)? [10]:
13. If you are adding a second Luna to the initial DSM node, repeat the steps in this section to add it now before
adding DSM nodes to the cluster.
Verifying the Luna status
Confirm that the Luna is connected properly. Change back to the HSM menu and, type:
0001:hsm$
luna show
HA auto recovery: enabled
HA recovery mode: activeEnhanced
Maximum auto recovery retry: 500