Skip to main content
Skip table of contents

Cluster: Key Synchronization in a Cluster for Luna S790

Proceed as follows to synchronize the key material:

For the following procedure make sure that an initialized PED and PED Keys are within reach.

The example below shows a 2 node cluster. For the sake of simplicity, the nodes are named as follows in the following sections:

Node1 is the primary node
Node2 is the secondary (or newly connected) node

Node2

To switch to another node click on the appropriate entry for the node in the drop-down list.

  1. The Start page of the appliance appears.

  2. Log into the EJBCA Hardware Appliance.
    On the Overview page the Application Overview shows that EJBCA has been stopped.
    The HSM Overview shows Alarm: On.

  3. Open the Security page.

  4. In the section Luna PCI HSM Configuration a warning indicates: Appliance joined a Cluster and is therefore in Factory Reset Mode.
    In the Internal HSM Status list the Alarm is On.

  5. Click Synchronize HSM in the warning message.

  6. The HSM Guided Setup window opens. If the entries are correct click Next Step.
    If this is not the case (e.g. remote PED not initialized) make the appropriate settings and then continue.
    For further information see HSM Initialization for Luna S790.

  7. Follow the prompts and attend to the PED. Run through and Finalize the HSM Initialization.

Synchronize Slots

  1. Back on the Security page the list with the general information of HSM starts with the entry:

    1. Description: Database Protection Token

    2. Status: Uninitialized (1/2) or (1/x) depending on how many nodes are connected

    3. Active: Inactive

    4. Actions: Synchronize Slot

  2. Click Synchronize Slot on the Database Protection Token to open the appropriate form.

    1. Enter a Description for the slot.

    2. Check the entry for the PED.

  3. If the entries are coherent continue with Synchronize Slot.

  4. For the HSM Slot Synchronization the setup form opens.
    Follow the prompts and attend to the PED.
    Run through and Finalize the HSM Slot Synchronization.

  5. Back on the Security page the list with the general information of HSM shows:

    1. Description: Database Protection Token

    2. Status: Initialized (2/2)

    3. Active: Active

    4. Actions: Deactivate

  6. Repeat the synchronization for each slot.
    Click Synchronize Slot eg. EJBCA Crypto Token #1 to open the appropriate form.

    1. Description for the slot is already set: here EJBCA Crypto Token #1.

    2. Authentication: provide the Slot PIN for EJBCA Crypto Token #1.

    3. Check the entry for the PED.

  7. If the entries are coherent continue with Synchronize Slot.

  8. For the HSM Slot Synchronization the setup form opens.
    Follow the prompts and attend to the PED.
    Run through and Finalize the HSM Slot Synchronization for EJBCA Crypto Token #1.

  9. Back on the Security page the list with the general information of HSM shows:

    1. Description: EJBCA Crypto Token #1

    2. Status: Initialized (2/2)

    3. Active: Active

    4. Actions: Decommission
      Deactivate
      Change PIN
      Synchronize

Node1

To switch to another node click on the appropriate entry for the node in the drop-down list.

  1. The Start page of the appliance appears.

  2. Log into the EJBCA Hardware Appliance.
    On the Overview page the Application Overview indicates that EJBCA is operational.

  3. Cluster Overview list appears.
    Node1: This Node, IP address is displayed
    Node2: Connected, IP address is displayed

  4. Click Admin Web next to EJBCA in Application Overview.
    The EJBCA Enterprise page opens.
    The installation is displayed.
    The node is not initialized.
    Create a New CA is already preselected.

  5. Open the CA Functions drop-down menu in the top menu bar.

  6. Select Crypto Tokens to open the Manage Crypto Tokens page.

  7. The EJBCA Crypto Token #1 is displayed in a list. Click on it.

  8. On the following page EJBCA Crypto Token #1 is displayed with further information.
    In the last row: Crypto Token currently does not contain any key pairs
    select in the rightmost drop-down field: Sign/Verify.
    Click Generate new key pair.

  9. The page will be updated and a key information row is displayed.
    Alias: signKey
    Key Algorithm: RSA
    Key Specification: 4096
    SubjectKey ID: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
    Action: Test or Remove Download Public Key

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.