10. Support and Maintenance
Customers are encouraged to obtain a support contract and regularly update their HSM
to the latest firmware release.
10.1. Security Advisories
If Entrust becomes aware of a security issue affecting nShield HSMs, Entrust will publish
a Security Advisory to customers. The Security Advisory will describe the issue and
provide recommended actions. In some circumstances the Security Advisory may
recommend you upgrade the nShield firmware and/or nShield Connect image file. In this
situation you will need to re-present an ACS quorum to the HSM to reload a Security
World. The HMS may need upgrading in the field. Consider this when you are deploying
the HSM and include the upgrade procedure in the maintenance documentation.
The Remote Administration feature supports remote firmware upgrade
of nShield Solo and nShield Connects and remote ACS card
presentation.
To see announcements made on a new nShield Security Advisory, we recommend that
you regularly check the nShield Announcements & Security Notices section of the
Entrust nShield Support Portal.
10.2. Application and Operating System patching
To maintain protection against threats that occur in the system environment operating
systems and applications should be updated in accordance with a patching policy as
described in
Patching
10.3. Connect fan tray module and PSU maintenance
The nShield Connect contains only two user-replaceable parts:
• The PSUs
• The fan tray module.
Replacing a PSU or fan tray module does not affect FIPS 140-2 validations for the nShield
Connect, or result in a tamper event. However, in the very rare event that a PSU or fan
tray module requires replacement, contact Support before carrying out the replacement
procedure.
nShield® Security Manual
Policy.
67 of 90
Need help?
Do you have a question about the nShield and is the answer not in the manual?