Chapter 6: Upgrade and Migration
Enabling Remote Administration for Upgraded V6100 Appliances
DSM Installation and Configuration Guide
Copyright 2009 - 2020 Thales Group. All rights reserved.
119
6A9B1481E3D6CEEB0D6D9B2C7635958A8CE8CB9A2BB3035961995429E4DC4929
8325783843B00705F4C541BF4ED5FF05F8C2EBB47A87F6D525631D00F47370F3
1DDA251A55366CC68725596483D26F03E715C716C5B81621D6EEA28C1A4BD0D5
E52F99C5A5257E8D4258FEEB384B4C46326D656368923545434453419235454D
53413136534841353132395369676E6174757265C584001A5B42B33DA5444F63
6ED39EF37FF086CCC7DE9512F676C30A469B8167E1534EB08F86913ADE3EBEAC
BF4A34E79B6BAF6BB1D1EE16413D37BDFF58CE6F7B122EE2003A92CFF4548B77
4AF280F0354A96F2668CBD1A0217322D40C239E5F39FEC142E25952594626338
99D8890E95A0FB23BA94DA8AA44118AA8ED804770D236F299C26C4387975F3A3
CDB62276BA301BC4DC112E246A4F000000000000000000000000000000000000
Warrant for module B0FF-8213-3E55 installed
HSM remote administration is enabled
SUCCESS: remoteadmin command ran successfully
On entering the contents of the warrant file, remote administration is enabled.
Replacing the ACS
After enabling remote administration, you need to replace the old card set with the new card set. Replacing the ACS
does not recreate a copy of the old ACS, but creates a completely new ACS to access the security world (the cluster)
that replaces the old ACS.
Note
You may also want to run a replace ACS procedure if you lose a card from the smart card set, or if a card is
compromised, or corrupted.
If you have a DSM backup created using the old card set, you should retain that old card set in case you want to
restore the backup, in which case,
do not
erase the old card set when prompted during the
replaceacs
procedure.
ACS replacement guidelines
l
Obtain a set of blank cards equal to N.
l
You cannot change K or N when you replace the ACS.
l
As a precaution, make a backup of your encrypted data before replacing the ACS. Note that this backup of the
encrypted data will require the current ACS (the ACS about to be replaced) in order to be restored. The new ACS
will not be able to restore this backup data, so you will want to keep the old ACS set until you are sure you no
longer need this backup.
l
You will be prompted to optionally erase your old ACS cards after you create the replacement set. This will
prevent the old ACS from being reused again. However, keep the old ACS if you want to restore any backup data
protected by the old ACS.
l
If you use pass phrases, make sure you do not forget them or the card will be inoperable.
Note
You can only replace the old ACS, you cannot change K or N during this procedure.
1. Start an SSH client session from the laptop or PC to the V6100 appliance, and log in using your CLI administrator
credentials.
2. To replace your ACS, insert one card from the quorum of the old card set into the old card reader, and at the
prompt type
replaceacs
and follow the instructions;
0002:vormetric$ hsm
0002:hsm$ hsm replaceacs