Using Transport Mode to avoid a board removal tamper
Transport Mode allows the HSM adapter to be removed from the host system PCI bus without causing a board removal tamper condition. A board removal tamper will remove all sensitive material from the HSM, including the HSM configuration, keys and certificates.
Only the Administrator can set the required transport mode on the HSM.
Use the command line utility ctconf with the -m option.
To set the Transport Mode
Caution
Transport Mode only disables the tamper response mechanism when removing the ProtectServer 3 PCIe adapter from the PCIe bus. Attempting any other hardware tamper procedure described in Hardware tamper procedures or physically attacking the ProtectServer 3 HSM will still result in a tamper response when a Transport Mode is enabled.
The numeric value following the -m switch will set the transport mode to one of the following:
Mode number | Mode name | Mode description |
---|---|---|
0 | No Transport Mode (Default) | Default mode that is applied when the HSM is installed and configured. This mode will tamper the HSM if it is removed from the PCI bus or any other hardware tamper procedure described in Hardware tamper procedures is attempted. |
1 | Single Transport Mode | HSM will not be tampered by removal from the PCI bus and will automatically revert to No Transport Mode the next time the HSM is reset or power is removed and restored. |
2 | Continuous Transport Mode | HSM will not be tampered by removal from the PCI bus. |