Chapter 3: DSM V6000 Hardware Appliance
nShield Connect Integration
DSM Installation and Configuration Guide
Copyright 2009 - 2020 Thales Group. All rights reserved.
63
nShield Connect Integration
DSM appliances that do not have a built in hardware security module (HSM)—DSM V6000 hardware and virtual
appliances—can now be configured to utilize an nShield Connect HSM to create and protect the DSM master key. The
nShield Connect series includes nShield C and nShield Connect XC, the DSM can be configured with either
of these appliances.
Note
The V6100 appliance does not support this feature. It has a built-in HSM.
Deployment
The figure below shows an example of a network HSM-enabled DSM HA cluster deployment. The DSM could be
virtual appliances on-premise or in the cloud, or V6000 appliances on-premise. The nShield Connect HSMs are
clustered for fault tolerance—if one of them fails, the Security World is still available to the DSMs via a peer node
Connect appliance.
Figure 3-5: Network HSM enabled V6000/virtual DSM HA cluster
The nShield Connect HSMs use the Security World paradigm to provide a secure environment for all HSM and key
management operations. The nShield Connect HSM has its own Security World, and the DSM (or DSM high
availability cluster) joins that Security World. For more about the Security World paradigm, see,
When a DSM appliance joins the nShield Connect HSM Security World, that DSM appliance is network HSM-enabled
and functions similarly to a V6100 appliance—with important differences in how backups are restored, see
up and Restoring network HSM-enabled DSM" on page 67
.
New CLI commands have been added to the HSM category of commands to enable and manage this feature. Refer to
the CLI chapter of the
DSM Administration Guide
for a detailed description of the new commands.
WARNING
Once a DSM appliance is converted to an HSM enabled appliance, it cannot be rolled
back to a non-HSM configuration unless you run the
config load default
command,
which wipes all configuration and resets the DSM appliance to the state in which it was
shipped.