2016 Symantec Corporation This document may be freely reproduced & distributed whole & intact including this copyright
notice.
55
Figure 3
–21 Initial Bootstrap Input Screen
For best security, select the master key storage location to be USB. If the option is
chosen, KEK1 is encrypted using an AES-256 bit key (KEK0) derived from the PIN
prior to being stored on the USB drive.
Whenever the module is power cycled or restarted, it requires this USB drive to be
plugged in, and the PIN to be input from the front panel keypad. Only with both
the USB drive and the correct PIN can the master keys be unlocked to gain access
the secure store. The Crypto Officer should maintain control of the USB drive.
If the option is not chosen, only the PIN (if setup) needs to be entered when the
module is power cycled or restarted.
The final stage of the bootstrap process is user setup. At least one user with the
Manage Appliance role, and one user with the Manage PKI role must be created.
The same user can be given one or more roles. The screen allowing configuration
of user(s) with these roles is shown in Figure 3-22.
Figure 3
–22 Bootstrap User Setup Screen
After creating the necessary user(s) the normal system login screen will appear
allowing the user to login, at which point they will have access to the full WebUI
to manage the SV3800/SV3800B/SV3800B-20. At this point a user with the
Manage Appliance role can create additional users but cannot give these users
the Manage PKI role. Only a user with the Manage PKI role can give this role to a
user.