Entrust nShield Connect 6000 Hardware And Setup Manual

Hide thumbs Also See for nShield Connect 6000:

Advertisement

nShield Security World
nShield v13.6.3
Hardware Install and
Setup Guides
08 July 2024

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the nShield Connect 6000 and is the answer not in the manual?

Questions and answers

Summary of Contents for Entrust nShield Connect 6000

  • Page 1 nShield Security World nShield v13.6.3 Hardware Install and Setup Guides 08 July 2024...
  • Page 2: Table Of Contents

    Table of Contents 1. Hardware install and setup guides......... .  ...
  • Page 3 4.2.3. Enabling optional features ........ ...
  • Page 4: Hardware Install And Setup Guides

    Chapter 1. Hardware install and setup guides 1. Hardware install and setup guides The hardware install and setup guides explain how to physically install and get started with your nShield HSMs. For instructions on installing the nShield Security World software, see the nShield Security World Software v13.6.3 Installation Guide.
  • Page 5: Nshield Network-Attached Hsms

    • For guidance on using your HSM and the Security World software, refer to the User Guide for your HSM. 2.1.1. Model numbers Model number Used for NH2047 nShield Connect 6000 NH2040 nShield Connect 1500 NH2033 nShield Connect 500 NH2068...
  • Page 6: Power And Safety Requirements

    Chapter 2. nShield Network-Attached HSMs Model number Used for NH2082 nShield Connect XC SCAP NH2089-B nShield Connect XC Base - Serial Console NH2089-M nShield Connect XC Mid - Serial Console NH2089-H nShield Connect XC High - Serial Console NH3003-B nShield Connect CLX Base - Serial Console NH3003-M nShield Connect CLX Mid - Serial...
  • Page 7: Handling The Hsm

    2.1.5.1. Temperature and humidity recommendations Entrust recommends that your module operates within the following environmental conditions. Environmental conditions Operating range (Min.  |  Max.)
  • Page 8: Physical Location Considerations

    2.1.6. Physical location considerations Entrust nShield HSMs are certified to NIST FIPS 140 Level 2 and 3. In addition to the intrinsic protection provided by an nShield HSM, customers must exercise due...
  • Page 9: Connecting Ethernet, Console And Power Cables

    Chapter 2. nShield Network-Attached HSMs storage or installation. For more information, see Handling an HSM.  You cannot install or configure the HSM remotely. To install the HSM in a 19” rack, follow the instructions supplied with your rack mounting kit. To install the HSM in a cabinet or a shelf, fit the four self-adhesive rubber feet (supplied with the HSM) to the bottom of the HSM.
  • Page 10 HSM is viewed from the back RJ45 port for a serial console cable If you connect only one Ethernet cable to the HSM, Entrust recommends that you connect it to Ethernet port 1. This is the ...
  • Page 11: Connecting The Serial Console

    Chapter 2. nShield Network-Attached HSMs • Identifying and replacing a faulty PSU, see the HSM Power Supply Unit Installation Sheet. 2.2.2. Connecting the Serial Console On supported HSM hardware variants (see Model numbers) there is a serial console port that provides access to a serial console command line interface that enables remote configuration of the HSM (See the HSM User Guide).
  • Page 12: Connecting The Optional Usb Keyboard

    Chapter 2. nShield Network-Attached HSMs 2.2.3. Connecting the optional USB keyboard Instead of using the controls on the front panel to configure the HSM, you can use a US or UK keyboard. You might find a keyboard easier for entering dates and IP addresses.
  • Page 13: Nshield Pcie Hsms

    Chapter 3. nShield PCIe HSMs 3. nShield PCIe HSMs 3.1. Prerequisites and product information This guide covers the following HSMs: • nShield Solo • nShield Solo XC • nShield 5s These Hardware Security Modules (HSMs) are for use in servers and appliances. •...
  • Page 14: Handling The Hsm

    Chapter 3. nShield PCIe HSMs Make sure that the power supply in your computer is rated to  supply the required electric power. The HSMs are intended for installation into a certified personal computer, server, or similar equipment. If your computer can supply the required electric power and sufficient cooling, you can install multiple modules in your computer.
  • Page 15 Chapter 3. nShield PCIe HSMs Operating temperature* 5°C (41°F) 55°C (131°F) Subject to sufficient airflow Storage temperature -5°C (-23°F) 60°C (140°F) Transportation -40°C (-40°F) 70°C (158°F) temperature Operating humidity Relative. Non-condensing at 30°C (86°F) Storage humidity Relative. Non-condensing at 30°C (86°F) Transportation humidity Relative.
  • Page 16 Chapter 3. nShield PCIe HSMs Storage temperature -5°C (-23°F) 60°C (140°F) Transportation -40°C (-40°F) 70°C (158°F) temperature Operating humidity Relative. Non-condensing at 30°C (86°F) Storage humidity Relative. Non-condensing at 30°C (86°F) Transportation humidity Relative. Non-condensing at 30°C (86°F) Altitude -100m (-328ft) 2000m (6561ft) Above Mean Sea Level The module is designed to operate in moderate climates only.
  • Page 17: Physical Location Considerations

    3.1.5. Physical location considerations Entrust nShield HSMs are certified to NIST FIPS 140 Level 2 and 3. In addition to the intrinsic protection provided by an nShield HSM, customers must exercise due diligence to ensure that the environment within which the nShield HSMs are deployed is configured properly and is regularly examined as part of a comprehensive risk mitigation program to assess both logical and physical threats.
  • Page 18: Module Pre-Installation Steps

    Chapter 3. nShield PCIe HSMs This guide covers the following HSMs: • nShield Solo XC • nShield 5s If you encounter any problems during the install process, refer to HSM Status indicators (nShield Solo and Solo XC) Morse  code error messages (nShield Solo and Solo XC), or HSM status indicators and error codes (nShield...
  • Page 19 Chapter 3. nShield PCIe HSMs Label Description Status LED Recessed clear button (Solo and Solo XC) or recovery mode button (5s) Physical mode switch Physical mode override jumper switch, in the Off position. When set to On, the mode switch (C) is deactivated. See the User Guide for your module and operating system for more information.
  • Page 20: Swap The Module Bracket

    Chapter 3. nShield PCIe HSMs 3.2.2. Swap the module bracket If the fitted module bracket is not the same height as the slot, swap it for the correct size. Both full height and low profile brackets are supplied with the module.
  • Page 21: Fitting A Smart Card Reader

    Chapter 3. nShield PCIe HSMs 1. Power off the system and while taking electrostatic discharge precautions, remove the module from its packaging. 2. Open the computer case and locate an empty PCIe slot. If necessary, follow the instructions that your computer manufacturer supplied. You must only install the HSM into a PCIe x4 slot, unless you are installing an nShield Solo (non-XC variant), which can ...
  • Page 22 Chapter 3. nShield PCIe HSMs If the Security World software has not already been installed, you must install the Security World Software by following the instructions in the nShield Security World Software v13.6.3 Installation Guide. Although methods of installation vary from platform to platform, the Security World Software should automatically detect the module on your computer and install the drivers.
  • Page 23: Nshield Usb Hsms

    Edge HSMs are connected to the same computer or VM, are not supported. Entrust does not recommend using the nShield Edge alongside other Entrust nShield HSMs on the same computer or VM. • For further information about the HSM, refer to the HSM User Guide section for your HSM.
  • Page 24: Fips

    To help maintain security: • Always inspect the USB cable and the nShield Edge before use, specifically the Entrust logo hologram in the tamper window shown below. (The nShield Edge Developer Edition does not have a hologram and tamper window.) If there are any signs of tampering, do not use the cable and the nShield Edge.
  • Page 25: Physical Location Considerations

    10 - 85% non-condensing 4.1.5. Physical location considerations Entrust nShield HSMs are certified to NIST FIPS 140 Level 2 and 3. In addition to the intrinsic protection provided by an nShield HSM, customers must exercise due diligence to ensure that the environment within which the nShield HSMs are deployed is configured properly and is regularly examined as part of a comprehensive risk mitigation program to assess both logical and physical threats.
  • Page 26: Connecting An Nshield Edge

    Chapter 4. nShield USB HSMs Change plan settings. 2. For Put the computer to sleep, select Never. Linux Set power options to never put computer to sleep. 4.2.2. Connecting an nShield Edge Do the following: 4.2.2.1. Windows Connect the nShield Edge to your computer, using the supplied USB cable. If your operating system detects the nShield Edge automatically, allow it to finish.
  • Page 27 4.2.3. Enabling optional features The nShield Edge supports a range of optional features, which can be enabled with a certificate or Activator card that you order from Entrust. To enable optional features, follow the instructions in the nShield Solo, Solo XC, and nShield Edge User Guide, or follow the instructions supplied with the certificate or Activator card.
  • Page 28 Chapter 4. nShield USB HSMs enquiry The following is an example of the output following a successful command: Module ##: enquiry reply flags none enquiry reply level Six serial number ####-####-####-#### mode operational version #.#.# speed index ### rec. queue ##..## ... rec. LongJobs queue ## SEE machine type ARMtype2 supported KML types DSAp1024s160 DSAp3072s256 mode operational...

Table of Contents