Luna SA HSM
Join a (missing or bad snippet) Node to an HA Cluster
DSM Installation and Configuration Guide
Copyright 2009 - 2020 Thales Group. All rights reserved.
108
Join a (missing or bad snippet) Node to an HA Cluster
When executed, the join command first checks to see if there is a Luna connected to the initial node. If it finds one,
then it implicitly performs a
Luna Add
function while joining the HA cluster.
Note
Add one node at a time.
DO NOT
add multiple nodes simultaneously. This applies to the initial node and all
subsequent nodes.
1. Log in to DSM node B.
2. Switch to the HA menu, type:
0000:DSM$
ha
3. Join the node to the cluster. Type:
0000:DSM$
join [longwait]
WARNING: This server node is about to join an HA cluster.
Please make sure the HA cluster is running and has this server node in its HA node list.
This may take several minutes. After join, please make sure this server node is in the same
security mode as other nodes.
4. To continue, type:
yes
.
5. Enter the name of the HA Initial Server host name to which you are joining this system.
Initial_Server=dsm95459.i.thales.com CAs_
Fingerprint=2F:C3:56:00:22:6D:8C:71:4A:3B:D8:39:09:62:23:18:A0:FF:77:6D
6. At the prompt, enter the administrator name for the Initial Security Server system, (this is the node that you just
connected to the Luna).
7. At the prompt, enter the DSM administrator password for the Initial Security Server system:
8. To continue, type:
yes.
9. Enter the IP address or host name of the Luna.
192.168.59.214: UZHnfG5tTURxZ8etW0VQHitywmiN5H8NgObKdF20j/M
The fingerprint above should match the RSA output of the
'sysconf fingerprint ssh' lunash command on the Luna SA
10. Enter the Luna administrator username.
11. Enter the Luna administrator the password.
12. (PED-authenticated Luna only) Enter the partition password set by the crypto officer.
13. Enter the HSM/Luna partition ID number to which you are registering.
Note
Enter the same partition number that you used for the initial node.
14. Enter hostname or IP address of
this
DSM.
This node may have multiple IP addresses. All of the agents will have to connect to the
Security Server using the same IP.
Enter the host name of this node. This will be used by Agents to talk to this Security
Server.
15. Enter the host name of this node. If the name is already correct, hit
Enter
.