Chapter 3: DSM V6000 Hardware Appliance
nShield Connect Integration
DSM Installation and Configuration Guide
Copyright 2009 - 2020 Thales Group. All rights reserved.
66
Figure 3-6: Configured HSM devices on DSM Web UI About page
Configuring High Availability for network HSM-enabled DSM
When configuring high availability (HA) for network HSM-enabled DSMs, Thales recommends the following:
l
Configure at least two nShield Connect HSMs in the Security World for fault tolerance. This means in the event
one of the appliances is not reachable for some reason, the Security World is still available.
Note
Client licenses will be required for each nShield Connect appliance that is configured for the DSMs—the
number of client licenses required per Connect appliance will be equal to the number of DSMs connected
to the nShield appliance.
l
Each network HSM-enabled DSM node in the HA cluster must be connected to at least two of the nShield
Connect HSMs in the Security World. This ensures that if one of the nShield Connect is not reachable for some
reason, the DSM nodes can still access the Security World of via the second nShield Connect.
A network HSM-enabled DSM HA cluster can be configured in one of two ways:
The first way is to configure DSMs as standalone nodes and enable network HSMs for each of them in the same
Security World. That is, all the DSMs must be configured with nShield Connect HSM(s) that are part of the same
Security World. You can now create a network HSM-enabled DSM cluster in the same way as for any other DSM
cluster
The high-level steps for to configure a network HSM-enabled DSM HA cluster in this way are:
1. Configure two nShield Connect HSMs and the associated RFS.
2. Configure the DSMs that are to be part of the HA cluster.
3. Add the DSMs individually to the nShield Connect Security World to make each DSM network HSM-enabled.
This means you must run the connect add command on each of the DSMs to add them to that Security World.
4. Add both nShield Connect HSMs to each of the DSMs.
Steps 1 to 4 are described here
"Configuring nShield Connect HSM with DSM" on page 64
, do this for each DSM
server that is to be part of the HA cluster.
5. Configure HA per the standard procedure described here,
Appendix B: "HA for V6x00 and Virtual Appliances" on
.
Managing network HSM-enabled DSM
To switch to another nShield Connect HSM in the Security World:
1. Open a CLI session on the network HSM-enabled DSM appliance to be moved to using another nShield Connect.
2. First add the nShield Connect appliance that you want the DSM node to use. Type the following at the prompt: