hagroup creategroup
Create an HA group. Use the -slot or -serialnumber options to specify the primary member for the group.
However, if you prefer to use the Luna Cloud HSM service as an active HA member, you must first edit the following toggle in the Chrystoki.conf/crystoki.ini configuration file (see Configuration File Summary):
[Toggles]
lunacm_cv_ha_ui = 0
CAUTION! Failover to Luna Cloud HSM is supported in an HA group with password-authenticated Luna partitions only. When configured in an HA group with multifactor quorum-authenticated Luna partitions, Luna Cloud HSM functions as a backup only.
NOTE Using Luna HSM Client 10.9.4 or older, apply labels no longer than 31 characters to a new HA group. The creation of an HA group, in client versions up to this point, allows input of as many as 32 characters for the group label, but incorrectly trims the 32nd character. For any label with fewer than 32 characters, that is not an issue. For a previously input 32-character label, the hagroup deletegroup command fails to recognize the label and does not delete the group.
Further, an attempt to create a second HA group with a label that differed from the first by only the 32nd character, would cause lunacm to see that as a duplicate and present an error saying the label is already being used.
WORKAROUND: When using the deletegroup command against an HA group with a label that was nominally 32 characters, provide just the first 31 characters for your group label. The deletion proceeds properly.
When creating an HA group using Luna HSM Client 10.9.4 or older, restrict labels to maximum 31 characters.
For a more in-depth look at HA groups and their options please see High-Availability Groups.
Syntax
hagroup creategroup {-serialnumber <serialnum> | -slot <slotnumber>} -label <label> -password <password>
| Argument(s) | Shortcut | Description |
|---|---|---|
| -serialnumber <serialnum> | -se | Serial number of the partition selected to be the primary member of the HA group. |
| -slot <slotnumber> | -sl | Slot number of the partition selected to be the primary member of the HA group. |
| -label <label> | -l | Label for the HA group being created. |
| -password <password> | -p | Crypto Officer password |
Example
lunacm:> hagroup creategroup -serialnumber 154438865288 -label myHAgroup
Enter the password: ********
Warning: There are objects currently on the new member.
Do you wish to propagate these objects within the HA
group, or remove them?
Type 'copy' to keep and propagate the existing
objects, 'remove' to remove them before continuing,
or 'quit' to stop adding this new group member.
> copy
New group with label "myHAgroup" created with group number 1154438865288.
Group configuration is:
HA Group Label: myHAgroup
HA Group Number: 1154438865288
HA Group Slot ID: Not Available
Synchronization: enabled
Group Members: 154438865288
Needs sync: no
Standby Members: <none>
Slot # Member S/N Member Label Status
====== ========== ============ ======
0 154438865288 sa78-2 alive
Command Result : No Error
LunaCM v7.0.0. Copyright (c) 2006-2017 SafeNet.
Available HSMs:
Slot Id -> 0
Label -> sa78-2
Serial Number -> 154438865288
Model -> LunaSA 7.0.0
Firmware Version -> 7.0.1
Configuration -> Luna User Partition With SO (PW) Signing With Cloning Mode
Slot Description -> Net Token Slot
Slot Id -> 1
Label -> sa40-2
Serial Number -> 1238700701515
Model -> LunaSA 7.0.0
Firmware Version -> 7.0.1
Configuration -> Luna User Partition With SO (PW) Signing With Cloning Mode
Slot Description -> Net Token Slot
Slot Id -> 5
HSM Label -> myHAgroup
HSM Serial Number -> 1154438865288
HSM Model -> LunaVirtual
HSM Firmware Version -> 7.0.1
HSM Configuration -> Luna Virtual HSM (PW) Signing With Cloning Mode
HSM Status -> N/A - HA Group
Current Slot Id: 0