background image

© 2000-2016 Gemalto NV. All rights reserved. 
Part Number 007-002924-007 
Version 5.2 

Trademarks 

All intellectual property is protected by copyright. All trademarks and product names used or referred to are the 
copyright of their respective owners. No part of this document may be reproduced, stored in a retrieval system or 
transmitted in any form or by any means, electronic, mechanical, chemical, photocopy, recording or otherwise without 
the prior written permission of Gemalto. 

Gemalto Rebranding 

In early 2015, Gemalto NV completed its acquisition of SafeNet, Inc. As part of the process of rationalizing the product 
portfolios between the two organizations, the HSM product portfolio has been streamlined under the SafeNet brand. As 
a result, the ProtectServer/ProtectToolkit product line has been rebranded as follows: 

Old product name 

New product name 

Protect Server External 2 (PSE2) 

SafeNet ProtectServer Network HSM 

Protect Server Internal Express 2 (PSI-E2) 

SafeNet ProtectServer PCIe HSM 

ProtectToolkit 

SafeNet ProtectToolkit 

Disclaimer 

All information herein is either public information or is the property of and owned solely by Gemalto NV. and/or its 
subsidiaries who shall have and keep the sole right to file patent applications or any other kind of intellectual property 
protection in connection with such information. 

Nothing herein shall be construed as implying or granting to you any rights, by license, grant or otherwise, under any 
intellectual and/or industrial property rights of or concerning any of Gemalto’s information. 

This document can be used for informational, non-commercial, internal and personal use only provided that: 

 

The copyright notice below, the confidentiality and proprietary legend and this full warning notice appear in all 
copies. 

 

This document shall not be posted on any network computer or broadcast in any media and no modification of any 
part of this document shall be made. 

Use for any other purpose is expressly prohibited and may result in severe civil and criminal liabilities. 

The information contained in this document is provided “AS IS” without any warranty of any kind. Unless otherwise 
expressly agreed in writing, Gemalto makes no warranty as to the value or accuracy of information contained herein. 

The document could include technical inaccuracies or typographical errors. Changes are periodically added to the in-
formation herein. Furthermore, Gemalto reserves the right to make any change or improvement in the specifications 
data, information, and the like described herein, at any time. 

Gemalto hereby disclaims all warranties and conditions with regard to the information contained herein, including all 
implied warranties of merchantability, fitness for a particular purpose, title and non-infringement. In no event shall 
Gemalto be liable, whether in contract, tort or otherwise, for any indirect, special or consequential damages or any 
damages whatsoever including but not limited to damages resulting from loss of use, data, profits, revenues, or custom-
ers, arising out of or in connection with the use or performance of information contained in this document. 

Gemalto does not and shall not warrant that this product will be resistant to all possible attacks and shall not incur, and 
disclaims, any liability in this respect. Even if each product is compliant with current security standards in force on the 
date of their design, security mechanisms' resistance necessarily evolves according to the state of the art in security and 
notably under the emergence of new attacks. Under no circumstances, shall Gemalto be held liable for any third party 
actions and in particular in case of any successful attack against systems or equipment incorporating Gemalto products. 
Gemalto disclaims any liability with respect to security for direct, indirect, incidental or consequential damages that 

Summary of Contents for SafeNet ProtectServer PCIe HSM

Page 1: ...SafeNet ProtectServer PCIe HSM Installation Guide ...

Page 2: ...mputer or broadcast in any media and no modification of any part of this document shall be made Use for any other purpose is expressly prohibited and may result in severe civil and criminal liabilities The information contained in this document is provided AS IS without any warranty of any kind Unless otherwise expressly agreed in writing Gemalto makes no warranty as to the value or accuracy of in...

Page 3: ...week Your level of access to this service is governed by the support plan arrangements made between Gemalto and your organization Please consult this support plan for further information about your entitlements including the hours when telephone support is available to you Contact method Contact Address Gemalto NV 4690 Millennium Drive Belcamp Maryland 21017 USA Phone Global 1 410 931 7520 Austral...

Page 4: ...Revision History Revision Date Reason A 14 March 2016 Release 5 2 ...

Page 5: ... HSM Access Provider Installation 5 Smart Card Reader Installation 5 Completing Installation 7 Chapter 3 Troubleshooting 8 Overview 8 Known Issues 8 Problem 8 Solution 8 Problem 8 Solution 8 Problem 8 Solution 9 Problem 9 Solution 9 Simple Fault Diagnosis 9 Fault Diagnosis Utilities 9 Fault Diagnosis Procedure 9 Chapter 4 Hardware Reference 10 Adapter Modification for External Tamper Detectors 10 ...

Page 6: ...THIS PAGE INTENTIONALLY LEFT BLANK ...

Page 7: ...is manual is provided as an instructional aid for the installation of a SafeNet ProtectServer cryptographic services hardware adapter Installation of the associated SafeNet ProtectServer PCIe HSM Access Provider package PTKpcihsm2 is described in the companion manual SafeNet ProtectServer HSM Access Provider Installation Guide The SafeNet PCI HSM Access Provider package includes the device driver ...

Page 8: ...THIS PAGE INTENTIONALLY LEFT BLANK ...

Page 9: ... connector suitable to mate with the tamper detect connector on the ProtectServer adapter detailed at the beginning of Appendix A 4 Install the SafeNet ProtectServer PCIe HSM card in the host computer system 5 Install the HSM Access Provider package that includes the device driver and confirm the correct operation of the adapter and driver installation 6 Use the included USB to serial cable to att...

Page 10: ...ou can use the ctconf command to test the condition of the battery If the Battery Status indication does not report as GOOD backup the HSM keys before powering down the PC to avoid losing the keys Note Disconnecting the battery deletes all key material on the HSM Ensure that you back up you HSM before disconnecting the power The keys are not deleted immediately Capacitors continue to supply power ...

Page 11: ...e consult the documentation accompanying your host system motherboard If you are using a tamper detection device route the cable to it before closing the computer cover PCI HSM Access Provider Installation After successful installation of the adapter the next steps are to 1 Install the HSM Access Provider package PTKpcihsm2 2 Confirm the correct operation of the adapter and driver package These st...

Page 12: ...ied with the ProtectServer product also requires connection to a PS 2 port for its power Many newer servers have USB ports but do not provide a PS 2 connection The options are Connect a PS 2 to USB adapter cable pink between the card reader and a USB port on the host computer If you prefer to not expose USB ports on your crypto server for security reasons then connect a PS 2 to USB adapter cable b...

Page 13: ...Provider installation to make use of the ProtectServer you will need to install the supplied SafeNet API or net server software Please refer to the installation instructions in the appropriate manual such as the SafeNet ProtectToolkit C Installation Guide ...

Page 14: ...ion or is left in an unstable state Solution This fault can occur if there are no free IRQs that can be assigned to the device Make sure the device is assigned an IRQ The IRQs assigned to devices are usually displayed when a system is powered up Problem The system locks up after installation of the HSM Access Provider device driver package This may happen if a prior version of the device driver ex...

Page 15: ...ese are installed as part of the ProtectServer PCI HSM Access Provider installation There are two utilities hsmstate and hsmreset Further information about these utilities beyond what is covered in this chapter can be found in the HSM Access Provider Installation Guide Fault Diagnosis Procedure From a command prompt execute hsmstate The output from the utility should include NORMAL mode Responding...

Page 16: ...ur tamper device s two wire cable in order to insert into the tamper detection socket on the ProtectServer adapter Crimp a pair of Molex 50212 8100 2mm WTB crimp terminals to the ends of the wires coming from your tamper switch and insert the crimped terminal sockets into the Molex connector housing Plug the connector end of the assembled cable into the tamper detect socket on the PCIe adapter In ...

Page 17: ... in a powered system The RTC performs a check of battery level daily If a low battery warning is detected on an adapter that has been un powered removed from a system then the data in the memory can be considered suspect If a low battery warning is detected on an adapter that has been continuously powered then the data in memory can be trusted for you to make a backup before proceeding with batter...

Reviews: