Resetting the Luna PCIe HSM 7 to Factory Condition

These instructions will allow you to restore your Luna PCIe HSM 7 to its original factory configuration. The HSM is zeroized, all partitions erased, and HSM policies are returned to their default settings. If you have performed firmware updates, those remain in place, and are not affected by this procedure.

To roll back the HSM firmware to the previous version, see Rolling Back the Luna HSM Firmware.

For eIDAS compliance, hsmrecover function is added to factoryreset commands - see Stored Data Integrity.

The standalone hsmrecover tool in the tools folder performs the same action, but can present additional messages that might be useful to Support engineers.

Prerequisites

>Only the HSM SO can perform factory reset.

>If you have STC enabled on the HSM, disable it by turning off HSM policy 39 before continuing (see Setting HSM Policies Manually).

To reset the HSM to factory condition

1.Set the active slot to the admin partition and log in as HSM SO.

lunacm:> slot set -slot <slotnum>

lunacm:> role login -name so

2.Reset the HSM to factory settings.

lunacm:> hsm factoryreset