Chapter 2: DSM V6100 Hardware Appliance
Administrator Card Set (ACS)
DSM Installation and Configuration Guide
Copyright 2009 - 2020 Thales Group. All rights reserved.
19
l
Enables operational simplicity and efficiency
Requirements
Remote HSM Administration only applies to the V6100 appliances that have DSM software v6.0 or later installed.
Remote administration needs to be turned on from the CLI before you can begin to use it.
To use the remote HSM administration feature, the following are required:
l
A remote card reader or trusted verification device (TVD) and smart cards set. These must be ordered separately,
contact your Thales Sales representative for more information.
l
V6100 appliance with DSM software (v6.0 or later)
l
Client system (e.g. laptop, PC outside the data center) on which to install the remote administration software and
connect the TVD.
See
"Enable remote administration" on page 39
for details.
Note
If you choose not to enable remote HSM administration, you can continue to use the original card reader
and card set that came with your DSM V6100 appliance.
Administrator Card Set (ACS)
The ACS is used to secure and manage the HSM. It creates a logical boundary called a Security World, within which
keys can be securely managed. You must create an ACS for your V6100 DSM environment.
The ACS must be initialized when you setup your initial DSM server. The ACS smart cards, read with a card reader
(trusted verification device, TVD) are required to carry out administrative operations for example;
l
Initial DSM configuration, specifically generating certificate authority using the DSM CLI command
system
security genca
l
Generating a certificate or Master Key rotation
l
Replacing the ACS
These are just a few of the administrative operations that require the ACS, see
"V6100 Operations that require the
for complete list of operations that require the ACS.
To configure remote HSM management for your DSM deployment, you must have a remote smart card reader (TVD)
and the associated set of smart cards. Contact Thales Sales and Support for more information about ordering these
accessories. See
"Upgrading the DSM" on page 115
for configuration and setup information.
Security World
A Security World is a logical security grouping of a DSM appliance and its associated objects and the Administrative
Card Set (ACS) that is used to create and manage that appliance and its associated objects. In the case of a high
availability deployment, all the DSM appliances and their associated objects in the cluster, are members of the same
Security World.
The ACS is required to access a DSM, and in an HA environment, the same ACS is required to access the HA DSM
nodes. The ACS creates the Security World to which the DSM belongs. In an HA deployment, all DSMs in the same
cluster belong to the same Security World and require the same ACS to carry out administrative functions, for
example, adding new DSMs to a cluster. Each card set consists of a number of smart cards,
N
, of which a smaller
number,
K
, is required to authorize an action. That required number
K
is known as the quorum.