Chapter 3: DSM V6000 Hardware Appliance
Configuring a V6000 Appliance
DSM Installation and Configuration Guide
Copyright 2009 - 2020 Thales Group. All rights reserved.
59
8. If a card is not inserted in the reader, you will be prompted to insert one. If a previously used (written) card is
inserted, you will be prompted to overwrite it. A previously used card is referred to as an ‘unknown’ card and a
used card that has been erased is referred to as a ‘blank’ card.
You will be prompted to enter a passphrase, this is optional
CAUTION
Do not lose this passphrase or your cards will be unusable.
Module 1 slot 0: Enter new passphrase:
Module 1 slot 1:- no passphrase specified - overwriting card
Module 1 slot #1: Processing . . .
Module 1: 1 card of 2 written
Module 1 slot 0: remove already-written card #1
Module #1 Slot #0: Remove card.
Module 1 slot 0: empty
Module #1 Slot #0: Insert appropriate card.
Checking Modules and reading cards ...
Module 1 slot 0: unknown card
Module 1 slot 0: Overwrite card? (press Return).
Module 1 slot 0: Enter new passphrase: .
Module 1 slot 1:- no passphrase specified - overwriting card
Module #1 slot #1: Processing . . .
This process continues until you have created your N cards. The following message is displayed after the last
card is written:
Card writing complete.
security world generated on module #0; hknso = f7387fed7f52625bc06b79607bb4b0afdd93a6b1
The hash value above, is the same hash value that will be displayed when you create an HA node. You can
compare the hash values to verify a successful creation.
CAUTION
Do NOT remove the card from the smart card reader until the server private key is
generated.
9. You can now remove the smart card from the reader.
Creating and signing the server certificates...
done
CA and Server certificates have been generated successfully.
JBoss vault keystore password have been completed successfully.
You may now start the Security Server
Stopping Security Server
Stopping data store
Starting data store
Starting Security Server
SUCCESS: The CA and security certificates are re-generated and the Security Server software
is restarted.
Regenerating CA will make certificates at HA node servers and agents invalid. You may need
to:
- Re-sign certificates at each HA node server
- Cleanup and re-register each agent
0002:system$
Your initial DSM with HSM is now configured.