Show the Table of Contents
Declassify the HSM Appliance
For full declassification [ Remove the unit from service, clear the HSM of all your material, clear the appliance of all identifying information ] of a Luna SA appliance, and assuming that you can power the appliance and gain admin access, follow these steps:
- Rotate all logs.
lunash:> syslog rotate
- Delete all files in the SCP directory.
lunash:> sysconf cleanup scp
- Delete all logs:
lunash:> syslog cleanup
- Return the appliance to factory-default settings.
lunash:> sysconf config factoryReset
- Delete any backups of settings.
lunash:> sysconf config clear
- Push the decommission button (small red button, inset in the Luna SA back panel).
- Power down the appliance.
- Power up the appliance. At this point, the HSM internally issues and executes a zeroize command to erase all partitions and objects. If there are a lot of partitions and/or objects on the HSM, zeroization can take a long time. The KEK is already gone at that point – erased as soon as the button is pressed – so the step of erasing partitions and objects is for customers subject to especially rigid declassification protocols.
See Also
Show the Table of Contents