Local PED Setup

A Local PED connection is the simplest way to set up the SafeNet Luna PED. In this configuration, the PED is connected directly to the HSM card. It is best suited for situations where all parties who need to authenticate credentials have convenient physical access to the HSM. When the HSM is stored in a secure data center and accessed remotely, you must use a Remote PED setup.

Setting Up a Local PED Connection

The SafeNet Luna Network HSM administrator can use these directions to set up a Local PED connection. You require:

>SafeNet Luna PED with firmware 2.7.1 or newer

>USB mini-B to USB-A connector cable

>Luna PED DC power supply (if included with your Luna PED)

To set up a Local PED connection

1.Connect the Luna PED to the HSM using the supplied USB mini-B to USB-A connector cable.

NOTE   To operate in Local PED-USB mode, the PED must be connected directly to the HSM card's USB port, and not one of the other USB connection ports on the appliance.

This rule does not apply for local PED authentication to a locally attached G7-based backup HSM. In this case you connect a remote PED to one of the appliance USB ports and connect to the pedserver service running on the appliance at IP address 127.0.0.1. See Backup and Restore Using a G7-Based Backup HSM for more information.

2.PED version 2.8 and above is powered via the USB connection. If you are using PED version 2.7.1, connect it to power using the Luna PED DC power supply.

As soon as the PED receives power, it performs start-up and self-test routines. It verifies the connection type and automatically switches to the appropriate operation mode when it receives the first command from the HSM.

3.If you prefer to set the operation mode to Local PED-USB manually, see Changing Modes.

The Luna PED is now ready to perform authentication for the HSM. You may proceed with setting up or deploying your SafeNet Luna Network HSM. All commands requiring authentication (HSM/partition initialization, login, etc.) will now prompt the user for action on the locally-connected Luna PED.

PED Actions

There are several things that you can do with the Luna PED at this point:

>Wait for a PED authentication prompt in response to a LunaSH or LunaCM command (see Performing PED Authentication)

>Create copies of your PED keys (see Duplicating Existing PED Keys)

>Change to the Admin Mode to run tests or update PED software (see Changing Modes)

>Prepare to set up a Remote PED server (see About Remote PED)