EasyManua.ls Logo

SafeNet Luna SA User Manual

SafeNet Luna SA
109 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
Page #1 background imageLoading...
Page #1 background image
Luna SA
Configuration Guide

Table of Contents

Question and Answer IconNeed help?

Do you have a question about the SafeNet Luna SA and is the answer not in the manual?

SafeNet Luna SA Specifications

General IconGeneral
BrandSafeNet
ModelLuna SA
CategoryServer
LanguageEnglish

Summary

PREFACE

About the Configuration Guide

Overview of the document's purpose and structure, including key sections and their page numbers.

Document conventions

Explains standard conventions used for user interface and important information alerts.

Support Contacts

Details how to contact technical support for installation, registration, or operation issues.

CHAPTER 1 Planning Your Configuration

Roles

Describes the multiple identities and functions available to map to roles and functions in an organization.

Named Administrative Users and Their Assigned Roles

Details the default and custom administrative user accounts and their assigned roles.

Implications of Backup and Restore of User Profiles

Explains the consequences of restoring user profiles from backup, including potential data loss or security issues.

Security of Shell User Accounts

Discusses security considerations for shell accounts, especially in exposed network positions.

Crypto Officer & Crypto User

Explains the subdivision of the Partition Owner role into Crypto Officer and Crypto User for enhanced security.

How the Roles are Invoked

Details how administrative and user roles are invoked and managed within the system.

Bad Login Attempts

Describes the system's response to multiple failed login attempts for security.

Domain Planning

Covers planning for cloning domains for HSM SO space and partitions.

Luna PED Planning

Guides planning for PED Key options and choices before actions that invoke PED Keys.

What each PED prompt means

Explains the meaning of prompts from the PED when key/access secrets are invoked.

CHAPTER 2 Configure the Luna Appliance for your Network

Gather appliance network setting information

Details essential network parameters and information required before configuration.

Client Requirements

Lists software and system requirements for client workstations connecting to the appliance.

Recommended Network Characteristics

Provides recommendations for bandwidth, latency, and network settings for optimal Luna appliance performance.

Open a Connection

Guides on establishing an initial serial connection to the Luna appliance for configuration.

First Login & Changing Password

Details the initial login process and changing the default administrative password.

Set System Date and Time

Explains how to set the system date, time, and timezone for accurate operation and certificates.

Configure IP and Network Parameters

Guides on setting the appliance's IP address, subnet mask, gateway, and DNS settings.

Make Your Network Connection

Instructions for establishing an ethernet connection to the network after configuration.

Generate a New HSM Server Certificate

Describes generating a new server certificate for enhanced security.

CHAPTER 3 HSM Initialization

What if I make a mistake?

Provides guidance on handling authentication errors during HSM initialization.

Recover the SRK

Explains the recovery process for the Secure Recovery Vector (SRK) if the HSM was shipped in Secure Transport Mode.

Preparing to Initialize a Luna SA HSM [PED-version]

Outlines the steps required before initializing a PED-version Luna SA HSM, including checking its state.

Start a Serial Terminal or SSH session

Guides on establishing a serial terminal or SSH connection for HSM initialization.

CHAPTER 4 HSM Capabilities and Policies

Set HSM Policies (Password Authentication)

Describes how to modify HSM policies for Password Authentication.

Set HSM Policies - PED (Trusted Path) Authentication

Details how to modify HSM policies for PED (Trusted Path) Authentication.

CHAPTER 5 Creating a Partition on the HSM

Prepare to Create a Partition (Password Authenticated)

Outlines the steps for creating an HSM Partition using Password Authentication.

Create the Partition [PW]

Guides on creating an HSM Partition and setting its password.

Prepare to Create a Partition (PED Authenticated)

Details the process for creating an HSM Partition using PED (Trusted Path) Authentication.

Create (Initialize) the Partition - PED Authenticated

Guides on creating and initializing an HSM Partition using a PED.

Record the Partition Client Password (PED-Auth HSMs)

Instructs on how to record the generated partition client password for authentication.

CHAPTER 6 Partition Policies

View the Partition Policies

Shows how to display the current policies of a created HSM Partition.

Set Partition Policy

Provides instructions on how to modify a Partition Policy for a given Partition.

CHAPTER 7 Prepare the Client for Network Trust Link

Preparing the Client

Outlines the steps for preparing a client system for network connection and certificate exchange.

Import a Server Cert

Guides on importing the HSM appliance server certificate onto the client.

Prepare a Network Trust Link - Windows

Details creating a Network Trust Link with the Luna SA appliance from Windows.

Register the HSM Server Certificate with the Client (Windows)

Explains how to register the HSM server certificate with a Windows client.

Create a Client Certificate (Windows)

Guides on creating a client certificate and private key for Windows clients.

Export a Client Cert to an HSM Appliance (Windows)

Details sending the client certificate to the HSM appliance from Windows.

Prepare a Network Trust Link - UNIX/Linux

Details creating a Network Trust Link with the Luna SA appliance from UNIX/Linux.

Create a Client Certificate (UNIX)

Guides on creating a client certificate and private key for UNIX/Linux clients.

Export a Client Cert to an HSM Appliance (UNIX)

Details sending the client certificate to the HSM appliance from UNIX.

Register the Client Certificate to an HSM Server

Explains registering the client certificate with the HSM Server.

CHAPTER 8 Assign a Client to an HSM Partition

Assign a Client to a Partition

Assigns a registered client to a specific HSM Partition.

Verify Your Setup

Guides on verifying the client and HSM configuration and registration.

CHAPTER 9 Optional Configuration Tasks

Configure a host trust link (HTL)

Explains configuring Host Trust Links for secure connections to trusted hosts.

Configure the Luna SA appliance to use a Network Time Protocol (NTP) server

Details synchronizing the appliance with an NTP server for accurate time.

Configure multiple HSMs to operate in high-availability (HA) mode

Describes setting up multiple HSMs for redundancy and load balancing.

Related product manuals