If you have an existing Luna HSM configuration and you want to change from using a single cluster certificate to individual node certificates, or if you want to change from individual node certificates to a single cluster certificate, you need to reset your HSM configuration and recreate it from the beginning.
Warning:
When you reset your HSM configuration, Cryptographic Security Platform Vault permanently deletes all Admin keys stored on any HSM servers in the current configuration. It then generates a new Admin Key. Make sure you download this Admin Key and keep it securely in case you need to restore your CSP Vault system to its current state. After reconfiguring the HSM settings you can generate a new Admin Key stored in the HSM(s).
- If any of your Cloud VM Sets use a KEK (Key Encryption Key) , the KEKs will not be deleted. However, Cryptographic Security Platform Vault will not be able to access those KEKs until you reconfigure the connection to the same partition on at least one of the HSM servers that you originally used. If a VM protected by a KEK is rebooted before the HSM server connection had been reestablished, the reboot will fail and VM will not be accessible to any users. For more information, see KEKs with Cloud VM Sets.
Procedure
- Log into the Cryptographic Security Platform Vault Management webGUI using an account with Security Admin privileges.
- In the top right, click the Switch to Appliance Management link.
- In the top menu bar, click Settings.
- In the System Settings section, click HSM Server Settings.
- Click Reset Server Settings and confirm the reset at the prompt.
- Reconfigure your HSM settings as described in Configuring CSP Vault as a Luna HSM Client with a Single Cluster Certificate or Configuring CSP Vault as a Luna HSM Client with Individual Node Certificates.