Sign In
Upload
Manuals
Brands
Sun Oracle Manuals
Host Adapter
Crypto Accelerator 6000 Board
Sun Oracle Crypto Accelerator 6000 Board Manuals
Manuals and User Guides for Sun Oracle Crypto Accelerator 6000 Board. We have
1
Sun Oracle Crypto Accelerator 6000 Board manual available for free PDF download: User Manual
Sun Oracle Crypto Accelerator 6000 Board User Manual (266 pages)
Version 1.1
Brand:
Sun Oracle
| Category:
Host Adapter
| Size: 3 MB
Table of Contents
Table of Contents
3
Regulatory Compliance Statements
15
Preface
19
Related Documentation
20
1 Product Overview
23
Product Features
23
New Features in the 1.1 Release
24
Key Features
24
Financial Services Support
25
Supported Applications
25
Supported Cryptographic Protocols and Algorithms
25
Diagnostic Support
26
Cryptographic Algorithm Acceleration
26
Hardware Overview
27
LED Displays
28
Direct Input Devices
29
Serial Port
29
USB Port
30
Dynamic Reconfiguration and High Availability
31
Load Sharing
31
Hardware and Software Requirements
32
Oracle Solaris 10 os on SPARC and X86 Platforms
32
X86 AMD Opteron Platforms Running Linux
32
Required Patches
32
2 Installing the Sun Crypto Accelerator 6000 Board
33
Handling the Board
34
Installing the Board on Oracle Solaris Platforms
34
Install the Hardware
34
Installing the Sun Crypto Accelerator 6000 Software with the Install Script
36
Install the Software with the Install Script
36
Directories and Files for Oracle Solaris Platforms
40
Removing the Sun Crypto Accelerator 6000 Software on Oracle Solaris Platforms with the Remove Script
41
Remove the Software with the Remove Script on the CD-ROM
41
For Oracle Solaris 11, Remove the Software with the Remove Script
42
Installing the Software on Oracle Solaris Platforms Without the Installation Script
43
Install the Software Without the Install Script
43
Removing the Software on Oracle Solaris Platforms Without the Remove Script
45
Delete Existing Keystores
45
Remove the Software Without the Remove Script
46
Installing the Sun Crypto Accelerator 6000 Board on Linux Platforms
46
Install the Sun Crypto Accelerator 6000 Hardware on Linux Platforms
47
Install the Sun Crypto Accelerator 6000 Software on Linux Platforms with the Install Script
47
Installing the Sun Crypto Accelerator 6000 Software on Linux Platforms Without the Install Script
48
Install the Software Without the Install Script
48
Directories and Files for Linux Platforms
49
Removing the Sun Crypto Accelerator 6000 Software on Linux Platforms
50
Removing the Sun Crypto Accelerator 6000 Software with the Remove Script
50
Remove the Software with the Remove Script
51
Remove the Software Without the Remove Script
51
Migrating Back to Version 1.0 from 1.1
52
Back up the 1.0 Keystore
52
Restore the 1.0 Software and Firmware
52
3 Administering the Sun Crypto Accelerator 6000 Board
55
Using the Scamgr Utility
56
Device and Keystore Security Officers
56
Scamgr Syntax
57
Scamgr Options
57
Modes of Operation
58
File Mode
59
Interactive Mode
59
Single-Command Mode
59
Scamgr Secure Communication
60
Initializing the Board with Scamgr
60
Board Initialization
61
Perform a Board Initialization
61
Keystore Initialization
62
Perform a Keystore Initialization and Create a New Keystore
62
Performing a Keystore Initialization to Use an Existing Keystore
63
Perform a Keystore Initialization and Use an Existing Keystore
64
Authentication and Logging in and out with Scamgr
65
Scamgr Prompt
65
Log in to a Board with Scamgr
66
Log in to a New Board
66
Log in to a Board with a Changed Remote Access Key
67
Log in to Another Board
69
Quitting the Scamgr Utility
70
Quit the Scamgr Utility
70
Entering Commands with Scamgr
70
Entering Scamgr Commands
70
Scamgr Commands
71
Getting Help for Commands
78
Managing Keystores with Scamgr
79
Multiple Keystore Support
79
Naming Requirements
80
Password Requirements
81
Change Password Requirements
81
Set the Password Requirements
81
Change Passwords
82
Managing Security Officers and Users
82
Populate a Keystore with Security Officers
82
Populate a Keystore with Users
83
List Security Officers
84
List Users
84
Delete Users
85
Disable Users
85
Enable Users
85
Delete Security Officers
86
Backing up Configuration and Keystore Data
86
Back up a Device Configuration
86
Back up a Master Key
87
Backup a Keystore
88
Lock a Master Key to Prevent Backups
89
Locking Keystores to Restrict Access
89
Enable a Locked Keystore to Enable Access
90
Lock a Keystore to Restrict Access
90
Disable a Locked Keystore to Prevent Access
91
Multi-Admin Authentication
91
Assign Security Officers the Multi-Admin Role
92
Managing Multi-Admin Mode with Scamgr
92
Remove a Security Officer from the Multi-Admin Role
92
Set a Multi-Admin Command Timeout
93
Set the Minimum Number of Security Officers Required to Authenticate Multi-Admin Commands
93
Disable Multi-Admin Mode
94
Enable Multi-Admin Mode
94
Add Additional Security Officers to the Multi-Admin Role
95
Cancel a Multi-Admin Command Originated by the Initiating Security Officer
96
Allow a Multi-Admin Command to Time out
97
Attempt to Execute a Multi-Admin Command Without Multi-Admin Role Permissions
98
Log in to a Board During a Multi-Admin Command as a Security Officer Not in the Multi-Admin Role
98
Managing Boards with Scamgr
99
Display Board Status
99
Set the Auto-Logout Time
99
Load New Firmware
100
Rekey the Board
101
Reset the Board
101
Perform a Software Zeroize on the Board
103
Use the Scamgr Diagnostics Command
103
Direct Board Administration
104
USB Backup Support
105
Using the Scadiag Utility
107
Scadiag Options
108
Scadiag Option Examples
109
Managing Services for Oracle Solaris Platforms
112
Start and Stop the Services
112
Service Configuration Parameters
113
List Service Configuration Parameters
114
Modify Service Configuration Parameters
115
Enabling Optional Cryptographic Algorithms
115
Enable the SHA-512 Algorithm
115
Enable the HMAC (MD5 or SHA1) Algorithm
116
Enable the Multi-Part MD5 Algorithm
116
Enable the Multi-Part SHA1 Algorithm
116
Enable the Multi-Part SHA512 Algorithm
116
Enable the RC2 CBC Algorithm
116
Additional Instructions for Administering the Board on Linux Platforms
116
Scadiag Program
117
Scamgr Program
117
Start the Board on a Linux Platform
117
Stop the Board on a Linux Platform
117
4 Configuring Centralized Keystores
119
Centralized Keystore Overview
119
Keystore Virtualization
120
Configuring Centralized Keystores
121
Configuring the Directory Server with the Scakscfg Utility
121
Configuring the Scakiod Service to Use CKS
123
Scakiod Service Configuration Options
124
Configure the Scakiod Service to Use CKS (Oracle Solaris)
126
Configure the Scakiod Service to Use CKS (Linux)
127
Configuring the Scakiod Service to Use SSL with Simple Authentication
127
Configure Scakiod for Simple Authentication over SSL
127
Configuring the Scakiod Service to Use SSL with Client Certificate Authentication
129
Configure the Scakiod Service to Use SSL with Client Certificate Authentication
129
Adding the Certificate to the Agent Entry in the Directory Server
132
Add the Certificate to the Agent Entry in the DS
132
Configuring the Board to Join a Centralized Keystore
134
Join a Previously Configured Board to a Centralized Keystore
134
Join an Unconfigured Board to a Centralized Keystore
134
Troubleshooting CKS Issues
136
Cannot Contact Server
139
Initial Keystore Search Failed
139
Failed Binding to Server
139
Failed Binding to Server
140
Client Authentication Initialization Failed
140
5 Developing and Administering Financial Services
141
Financial Service Components Overview
142
Financial Services Library Initialization
143
Library Open Function Fs_Lib_Open()
144
Library Shutdown Function Fs_Lib_Close()
144
Session Establishment Function Fs_Session_Open()
145
Session Shutdown Function Fs_Session_Close()
146
Financial Services Data Types
146
Key Management Overview
147
Key Separation and Compartmentalization of Risk
147
Permitted Key Forms
148
Direct Key Loading
148
Enable the MFK
148
Load the MFK
148
Change the MFK
149
Load the Keks
149
Key Management Functions
149
Generate Key Function Fs_Generate_Key()
150
Import Key Function Fs_Import_Key()
151
Export Key Function Fs_Export_Key()
152
Translate Key Function Fs_Translate_Key()
153
Retrieve Object Function Fs_Retrieve_Object()
154
Status Function Fs_Status()
155
PIN Processing Functions
155
PIN Block Formats
156
ANSI/ISO Format 0
156
ISO Format 1
157
PIN Calculation Methods
157
Visa PVV Method
157
IBM-3624 Method
158
Personal Account Number
158
Pin
158
Pvki
159
PIN Verify Function Fs_Pin_Verify()
159
PIN Translate Function Fs_Pin_Translate()
160
Credit Card Processing Overview
162
Financial Services Library Function Fs_Card_Verify(3)
162
Enabling the Financial Services Feature
163
Enable Financial Services
163
Administering Financial Services
164
Administrative Commands
164
Direct Input Device
164
Financial Services Security Officers
164
Setting Financial Services Mode
164
6 Developing PKCS#11 Applications for Use with the Sun Crypto Accelerator 6000 Board
167
Board Administration
168
Slot Descriptions
169
Keystore Slot
169
Sun Metaslot
170
Configuring Sun Metaslot to Use the Sun Crypto Accelerator 6000 Keystore
170
Configuring Secure Failover for Sun Metaslot
171
Hardware Slot
172
PKCS#11 and FIPS Mode
173
Developing Applications to Use PKCS#11
174
Sun Crypto Accelerator 6000 PKCS#11 Implementation Specifics
174
Token Objects
174
Random Number Generator
175
Supported and Unsupported Functions
175
Software Attributes
176
Software Error Codes
177
Token Object Handles
178
Developing PKCS#11 Applications for Use with the Sun Crypto Accelerator 6000 Board on Linux Platforms
178
7 Installing and Configuring Sun Java System Server Software
179
Administering Security for Sun Java System Web Servers
180
Web Server Concepts and Terminology
180
Users
180
Keystores
181
Slots and Tokens
182
Preparing to Configure Sun Java System Web Servers
183
Populating a Keystore
184
Populate a Keystore
184
Installing and Configuring Sun Java System Web Server 6.1
185
Crejavate Java Trust Djavatjavabjavase
187
Register the Board with the Web Server
188
Generate a Server Certificate
189
Install the Server Certificate
192
Enable the Web Server for SSL
193
Installing and Configuring Sun Java System Web Server 7.0 Update 1
195
Register the Board with the Web Server
196
Install Sun Java System Web Server 7.0
196
Start the Sun Java System Web Server Administration Server
197
Disable Unused Tokens
198
Manage the Tokens
198
Pre-Set the Password for Tokens
198
Generate a Server Certificate
199
Install the Server Certificate
200
Deploy the Change
202
Enable the Web Server for SSL
203
Installing and Configuring Sun Java System Web Server on Linux Platforms
206
Configuring Sun Java System Web Servers to Start up Without User Interaction on Reboot
208
Create an Encrypted Key for Automatic Startup of Sun Java System Web Servers on Reboot
208
8 Installing and Configuring Apache Web Server Software
211
Installing and Configuring Apache Web Server on Oracle Solaris Platforms
211
Create a Private Key and Certificate
211
Enable Apache Web Server
213
Installing and Configuring Apache Web Server on Linux Platforms
214
Prepare Openssl Libraries
215
Compile Apache Web Server
216
Configure and Start Apache Web Server
216
9 Diagnostics and Troubleshooting
219
Diagnostic Software
219
Performing Sunvts Diagnostics
219
Performing Scamgr Diagnostics
220
Performing Scadiag Diagnostics
220
Disabling Crypto Traffic on Other Hardware Providers in Your System
220
Disable Other Hardware Providers
221
Reenable Other Hardware Providers
221
Examining and Reporting Kernel Statistics
221
Determine Cryptographic Activity with the Kstat Utility
222
Determining Cryptographic Activity on Linux Platforms
223
Determine Cryptographic Activity on Linux Platforms
223
Sun Crypto Accelerator 6000 Board Specifications
225
Connectors
225
Physical Dimensions
226
Power Requirements
227
Overview
229
Installing Opencryptoki Software
230
Build and Install Opencryptoki Software on SUSE10 SP1 Platforms
231
License Agreement
235
Third Party License Terms
238
Zeroizing the Sun Crypto Accelerator 6000 Hardware to the Factory State
245
Zeroize the Sun Crypto Accelerator 6000 Board with a Hardware Jumper
246
Index
261
Advertisement
Advertisement
Related Products
Sun Oracle Sun Storage 6000 Series
Sun Oracle Categories
Server
Storage
Switch
Control Unit
Racks & Stands
More Sun Oracle Manuals
Login
Sign In
OR
Sign in with Facebook
Sign in with Google
Upload manual
Upload from disk
Upload from URL