2 M-HSM Installation and Setup Scenarios
This section describes the following installation and setup options:
- Initial setup:
- Install all required software components.
- Update all required M-HSM server configuration files.
- Install the HSM module.
- Provision the M-HSM server.
- Create new Security World and Administrator Card Set (ACS).
- Generate all required M-HSM server keys.
- Exchange public encryption and public verify keys with the U-HSM.
- Import Diversified Factory Key Database (DFK DB) and the manufacturing keys received from the U-HSM.
- Post-Installation (maintenance) steps:
- Upgrade the HSM module firmware.
- Replace the HSM module.
- Import public keys of the U-HSM.
- Export public keys for sending to a U-HSM.
- Import new DFK DB and manufacturing keys for the target Microchip device(s).
- Replication of the existing M-HSM server (creates a copy of already provisioned M-HSM server):
- Install all required software components.
- Copy over Security World from the source M-HSM server.
- Copy over the M-HSM server software and configuration files.
- Copy over the existing DFK DB.
- Replace the HSM module.