HSM Troubleshooting
This section allows you to rectify HSM problems.
Log in to the Next Generation Hardware Appliance.
Open the Security page.
In the section HSM Troubleshooting click Restart to restart the current HSM driver.
The HSM Driver Status should be RUNNING under normal circumstances.
Troubleshooting for Luna S790 HSM
Exit Secure Transport Mode: Verification strings do not match
If the verification string does not match the verification string sent in the email, you should check the random string you entered for typos.
If there is a typo:
Click the Close button in the Exit Secure Transport Mode window.
Open the Security page if you are not automatically redirected there.
In the section HSM Troubleshooting click Restart
Wait until the Setup in Progress message disappears in the Luna PCI HSM Configuration section.
Restart the Exit Secure Transport Mode process.
Enter the random string correctly.
However, if there are no typos and the verification string does not match, there may be a security problem. In this case, be sure to contact support.
Clean up Slots
An additional function has been set up for Luna HSM users. Initialized slots that are not fully set up will continue to count towards the slot limit. Since the number of partitions supported by the license is limited to 100 slots, non-functional slots can be eliminated. To decommission partitions, a Clean Up button is activated as soon as there are HSM slots that are not functional.
Interaction with the PED is required for the following steps.
The blue PED Key (and for remote connections the orange PED Key) is also required.
Log in to the Next Generation Hardware Appliance.
Open the Security page.
In the section HSM Troubleshooting click Clean Up to start the process.
A new window Slots Cleanup opens.
Check Use Remote PED if applicable. Click Next Step.
A summary opens. Click Start Cleanup to start the process.
Follow the instructions on the PED to continue.
After all non-functional slots have been cleaned up click Finalize.
Background Process Cancellation and Timeout Handling
During setup operations the following cancellation constraints apply:
No Immediate Cancellation
It is not possible to interrupt an active setup-background process (e.g. while interacting with the PED is ongoing).
There is also no cancel/abort option available on the PED itself during interaction.
Cancel After Error
The cancel/abort option is only available if an error has occurred in the setup background process.
Recommended User Action
If a user wants to stop the process during an active PED interaction:Stop the current interaction.
Allow the process to time out naturally.
After this timeout, the background process is terminated with an HSM Error.
As soon as the error occurs, the cancel/abort option becomes available.
Important Notes:
Users cannot forcibly interrupt setup operations while PED interaction is ongoing.
Timeout is a way to terminate an undesired process.
After the timeout, a complete process abort is possible.