Replacing an nShield HSM on a Cryptographic Security Platform Vault Cluster

If you have a Cryptographic Security Platform Vault cluster on an nShield HSM, you can replace the HSM while maintaining the cluster. This procedure documents a 2-node cluster. If you have more than two nodes you will need to modify the instructions.

Before You Begin 

To replace the nShield HSM, make sure you have the following information available:

  • The HSM server name, server IP/FQDN, ESN, Port, and Keyhash for the replacement nShield HSM (HSM-2).
  • The Security World Bundle file for the replacement HSM. Both HSM-1 and HSM-2 must have the same security world inside of the Security World Bundle file. Please contact your  HSM Administrator to ensure that this is set up correctly.

    Tip: This information can be found in the sections on replacing, adding, or restoring an HSM to the Security World in chapters 2 and 9 of the nShield® Connect User Guide for Unix.

Procedure 

  1. Log into the Cryptographic Security Platform Vault Management webGUI using an account with Security Admin privileges.
  2. In the top right, click the Switch to Appliance Management link.
  3. In the top menu bar, click Settings.
  4. In the System Settings section, click HSM Server Settings.
  5. On the nShield HSM Server Settings page, click the Client List tab.
  6. Copy the Cryptographic Security Platform Vault IP addresses and keyhashes to notepad. You will need the IP address and keyhash of both the Cryptographic Security Platform Vault nodes (node-1 and node-2) to authenticate Cryptographic Security Platform Vault on the replacement nShield HSM (HSM-2).
  7. Use the IP address and keyhash to authenticate Cryptographic Security Platform Vault on nShield. Please see your nShield documentation.

    Important: For Cryptographic Security Platform Vault clusters, you will need to authenticate the IP address and keyhash for each cluster node.

  8. Copy the Security World Bundle from the replacement HSM-2 as world.zip and place it on your local machine.

  9. On the nShield HSM Server Settings, click the Server Settings tab and then select HSM-1.

  10. Replace the Server Name, Server IP/FQDN, Server ESN, Server Port and Server Keyhash of HSM-1 with the values for HSM-2.

  11. Click Apply.
  12. Select Actions > Upload Security World and upload the security world bundle for HSM-2.
  13. Test your connection with HSM-2.