When you reset your HSM configuration, keep the following in mind:

  • Cryptographic Security Platform Vault permanently deletes all Admin keys stored on any HSM servers in the current configuration. It then generates a new Admin key. Make sure you download this Admin Key and keep it securely in case you need to restore your Cryptographic Security Platform Vaultsystem to its current state.
  • If you are using Luna HSMs or Luna Cloud HSMs: 

    • If any of your Cloud VM Sets use a KEK (Key Encryption Key) , the KEKs will not be deleted. However, Cryptographic Security Platform Vault will not be able to access those KEKs until you reconfigure the connection to the same partition on at least one of the HSM servers that you originally used. If a VM protected by a KEK is rebooted before the HSM server connection had been reestablished, the reboot will fail and VM will not be accessible to any users. For more information, see KEKs with Cloud VM Sets.

      Important: You must disable the KEK setting in every Cryptographic Security Platform Vault for KMIP before you reset the HSM.

    • The Cryptographic Security Platform Vault client on the Luna HSM servers will not be deleted. If you want to remove the Cryptographic Security Platform Vault client from the Luna HSM server, you must do this manually on each Luna HSM server in your configuration.

  • If you are using both Luna HSMs and Luna Cloud HSMs you must reset both HSMs.

  • If you are using nShield HSMs: 

    • All keys will be deleted. You should disconnect all CSP Vaults from the HSM before resetting the HSM configuration.

    • If you have enabled HSM Root-of-Trust, you cannot reset the HSM server configuration.

Procedure 

  1. Log into the Cryptographic Security Platform Vault Management webGUI using an account with Security Admin privileges.
  2. In the top right, click the Switch to Appliance Management link.
  3. In the top menu bar, click Settings.
  4. In the System Settings section, click HSM Server Settings.
  5. Reset the server as follows:

    • For nShield, select Actions > Reset HSM Configuration.

    • For Luna HSM, select Actions > Reset Luna HSM Configuration.

    • For Luna Cloud HSM, select Actions > Reset Luna Cloud HSM Configuration.

  6. Confirm the reset at the prompt.