Skip to main content

Primus HSM - Management

The Primus HSM can be managed using the built-in touch display, the console, or the Decanus Terminal. Through these channels, administrators can perform all management tasks, such as viewing the device state and diagnostics, changing network settings, defining the security configuration, creating new Partitions, and issuing Setup Password to connect client applications.

For example, you can view hardware diagnostics as follows (temperature, fan speed, PSU status):

System Diagnostics Device Hardware

Detailed information about device management such as the menu tree and the command reference is documented in section 4 of the Primus HSM User Guide.

The following general concepts apply to device management:

  • Same feature set: All channel generally offer the same feature set (up to some minor exceptions). You can use any of them, depending on your preference.
  • Max one active session: The management session can only be active on at most one management channel. Logging in through another channel will terminate any existing session.
  • Authentication: The authentication/authorization and available roles are the same across all channels. All channels have a Device Password for basic access, and Security Officers for privileged access. For details, see Roles and Access Control.

Front Panel (UI)

Some Primus HSM devices allow management via the front panel built-in user interface:

  • X2/S2-Series come with a color touch display
  • X/S-Series feature an LC Display with the keypad apart
  • E2/E-Series do not support management via front panel

Console via Serial Port

All Primus HSM devices can be managed via command line interface (CLI) through the serial port by using a VT100 terminal emulator (e.g. Putty or iTerm). See section 11.1 "Serial Port" of the Primus HSM User Guide.

The type of serial port on the HSM varies by model:

  • X2/S2/E2-Series: RJ45 socket
  • X/S/E-Series: DB9 male socket

You will need a USB-to-Serial adapter. See this list of recommended adapters.

Front view of a Primus HSM CyberVault

Console via SSH

The same console that is accessible via a serial connection can also be accessed over SSH. This requires initial configuration of allowed SSH public keys via any of the other interfaces. See section 4.8 "SSH Management" of the Primus HSM User Guide for instructions.

info

If 2FA is enabled (X2/S2/X/S-Series), physical access to the device is required to insert cards into the card slots. See Authentication Mode for more information.

Remote Management - Decanus Terminal

Decanus is a tamper protected remote terminal for the Primus HSM. Decanus may comprise different firmware variants and applications, e.g.

  • HSM Device Administration
    • Enabling remote administration of up to 64 Primus HSM devices. Remote Administration (UI) requires the same authentication as with Front Panel (UI) and provides access to the same Menu Tree.
    • Restrictions: Power up of HSM, Initial Wizard execution.
  • HSM Partition Administration and Auditing
    • Enabling remote administration and audit of up to 64 single Primus HSM partitions (PSO, PAU)
  • Customer specific firmware applications

View the Decanus Terminal User Guide for a thorough walk-through and step-by-step guide on how to setup and use the Decanus Terminal.

HSM Device Administration

The Decanus Terminal in Device Administration mode communicates over a network using the configured Primus HSM management interface and TCP port (default: 2340).

The Decanus Terminal must first be paired with the Primus HSM to establish a secure connection. Enable remote administration in the Primus HSM configuration before use (requires appropriate licensing).

Pairing can be done for a single Decanus Terminal via the CLI or front panel. For bulk pairing, a Decanus configuration file can be loaded from a USB stick into the HSM. The HSM will generate a unique pairing key file for each terminal and automatically append the corresponding pairing information to the configuration file. File-based pairing can also be done during the initial setup wizard.

A blinking Access LED on the HSM indicates that the Decanus is successfully connected. Removing a paired Decanus Terminal can be done via the Primus HSM UI or CLI management.

HSM Partition Administration and Auditing

Pairing the Decanus Terminal in Partition Administration mode with an HSM requires:

  • enabling management on the Partition (user specific configuration)
  • creating a Partition Management Password for Decanus (requires additional licensing).

The Decanus Terminal Partition Administration mode connects to one of the configured Primus HSM API interfaces and corresponding ports (JCE/JCA, PKCS#11, MS CNG).

See Security Configuration for more information how to enable User specific configuration.
See Roles for more information about Partition Security Officer and Partition Auditor roles.

Get started withCloudHSM for free.
Other questions?Ask Sales.
Feedback
Need help?