Home >

Administration Guide > Security Effects of Administrative Actions > Summary of Outcomes of Security-affecting Actions

Summary of Outcomes of Security-affecting Actions

This table lists some major administrative actions that can be performed on the HSM, and compares relevant security-related effects. Use the information in this table to help decide if your contemplated action is appropriate in current circumstances, or if additional preparation (such as backup of partition content, collection of audit data) would be prudent before continuing.

Factory Reset HSM With Firmware <6.22.0

Domain Destroyed  
HSM SO Role Destroyed  
Partition SO Role Destroyed  
Auditor Role Destroyed  
Partition Roles Destroyed  
HSM or Partition/Contents HSM/Destroyed  
HSM Policies   Unchanged
RPV Unchanged  
Messaging   You are about to factory reset the HSM. All contents of the HSM will be destroyed. HSM policies and remote PED vector left unchanged.  

Factory Reset HSM With Firmware ≥6.22.0

Domain Destroyed  
HSM SO Role Destroyed  
Partition SO Role Destroyed  
Auditor Role Destroyed  
Partition Roles Destroyed  
HSM or Partition/Contents HSM/Destroyed  
HSM Policies   Reset
RPV
Messaging   You are about to factory reset the HSM. All contents of the HSM will be destroyed. HSM policies will be reset and the remote PED vector will be erased.

Zeroize HSM With Firmware ≥6.22.0

Domain Destroyed  
HSM SO Role Destroyed  
Partition SO Role Destroyed  
Auditor Role Unchanged
Partition Roles Destroyed  
HSM or Partition/Contents HSM/Destroyed  
HSM Policies   Unchanged
RPV Unchanged
Messaging   You are about to zeroize the HSM. All contents of the HSM will be destroyed. HSM policies, remote PED vector and Auditor left unchanged.

Change Destructive HSM Policy

Domain Unchanged
HSM SO Role Unchanged
Partition SO Role Destroyed  
Auditor Role Unchanged
Partition Roles Destroyed  
HSM or Partition/Contents HSM/Destroyed  
HSM Policies   Unchanged except for new policy
RPV Unchanged
Messaging   You are about to change a destructive HSM policy. All partitions of the HSM will be destroyed.

Apply Destructive CUF Update

Domain Destroyed
HSM SO Role Destroyed
Partition SO Role Destroyed  
Auditor Role Unchanged
Partition Roles Destroyed  
HSM or Partition/Contents HSM/Destroyed  
HSM Policies   Unchanged
RPV Unchanged
Messaging   You are about to apply a destructive update. All contents of the HSM will be destroyed.

HSM Initialize When Admin Not Initialized

Domain Destroyed
HSM SO Role Destroyed
Partition SO Role Destroyed  
Auditor Role Unchanged
Partition Roles Destroyed  
HSM or Partition/Contents HSM/Destroyed  
HSM Policies   Unchanged
RPV Unchanged
Messaging   You are about to initialize the HSM. All contents of the HSM will be destroyed.

HSM Initialize When Admin Initialized

Domain Unchanged
HSM SO Role Unchanged
Partition SO Role Destroyed  
Auditor Role Unchanged
Partition Roles Destroyed  
HSM or Partition/Contents HSM/Destroyed  
HSM Policies   Unchanged
RPV Unchanged
Messaging   You are about to initialize the HSM that is already initialized. All partitions of the HSM will be destroyed. You are required to provide the current SO password.

Non-Admin Partition Initialize When the Partition is Not Initialized

Domain Unchanged
HSM SO Role Unchanged
Partition SO Role Destroyed  
Auditor Role Unchanged
Partition Roles Destroyed  
HSM or Partition/Contents Partition/Destroyed  
HSM Policies   Unchanged
RPV Unchanged
Messaging   You are about to initialize the partition. All contents of the partition will be destroyed.  

Non-Admin Partition Initialize When the Partition is Initialized

Domain Unchanged
HSM SO Role Unchanged
Partition SO Role Destroyed  
Auditor Role Unchanged
Partition Roles Destroyed  
HSM or Partition/Contents Partition/Destroyed  
HSM Policies   Unchanged
RPV Unchanged
Messaging   You are about to initialize the partition that is already initialized. All contents of the partition will be destroyed. You are required to provide the current Partition SO password.