Luna Network HSM Appliance Software 7.7.0

Luna Network HSM 7.7.0 was released in October 2020.

>Download Luna Network HSM Appliance Software 7.7.0 (includes firmware update to Luna HSM Firmware 7.7.0)

New Features and Enhancements

Luna Network HSM 7.7.0 includes the following new features and enhancements:

Scalable Key Storage

Scalable Key Storage (SKS) is an optional feature that allows off-board storage of keys and objects in quantities greater than the capacity of an HSM - virtually unlimited storage, for use with your RSS (Remote Signing and Sealing) and other applications that require thousands or millions of keys. An SKS Master Key (SMK, which never leaves the HSM) securely encrypts extracted keys and objects, such that they remain within the HSM's security envelope, and can be reinserted (decrypted inside the HSM) for immediate use by your application.

Preserves key attributes through the life-cycle of a key.

Provides the option of new SKS function, or classic Luna "keys always in hardware" operation, on a partition-by-partition basis.

This feature also requires Luna HSM Firmware 7.7.0 or newer, and Luna HSM Client 10.3.0 or newer.

Per-Key Authorization

Per-Key Authorization (PKA) allows granular control of key material for applications requiring high assurance by providing authorization on a per-key basis.

This feature also requires Luna HSM Firmware 7.7.0 or newer, and Luna HSM Client 10.3.0 or newer.

STC Usability and eIDAS Compliant Security is Added

STC policy is improved, with fewer steps in setup. The use (and configuration) of Admin channel is removed. The partition identity is now a certificate.

See Client-Partition Connections.

This feature also requires Luna HSM Firmware 7.7.0 or newer, and Luna HSM Client 10.3.0 or newer.

NTLS Appliance Certificates Signed by Third Party CA

Luna Network HSM appliance now allows the use of communications-securing NTLS certificates from third-party Certification Authorities, while continuing to support use of self-signed certificates where desired.

See Creating an NTLS Connection Using Certificates Signed by a Trusted Certificate Authority.

Release 7.7.0 Advisory Notes

This section highlights important issues you should be aware of before deploying appliance software 7.7.0.

sysconf snmp trap set command now defaults to "inform"

Previously, sysconf snmp trap set -traptype command would default to "trap". This has changed with release 7.7.0; which adds the option "inform", the new default. If you had any scripts that relied on the default setting, they should now be adjusted to explicitly set the -traptype.

Change in network routing default requires precaution when updating

A change to network routing when updating to Luna Network HSM appliance version 7.7.0 or newer, from any prior 7.x version, can cause your appliance to become unreachable via network connection. Older appliance versions permitted the existence of multiple default routes. Beginning with appliance version 7.7.0, only one instance of the default route can exist.

Options for a successful update with minimal disruption are:

>Remove all but one instance of the ‘default route’, using the network route delete command, before upgrading from any pre-7.7.0 appliance software version.

>Connect locally via serial cable to perform the update, so your access to the network appliance is not lost when network connection becomes temporarily unavailable (pending proper network configuration).

Note also that if you re-image, going back to a pre-7.7.0 version, the routing table goes back to the old format and you must apply one of the above precautions again, to update.

If the above precautions are not taken and the appliance becomes unreachable, complete the following steps to restore connection to the appliance:

1.Connect locally via serial cable.

2.Delete all network interfaces. See network interface delete.

3.Configure a network interface to use a default route by doing one of the following:

Configure the network interface to use a static IP configuration while specifying the -gateway option. See network interface static.

Configure the network interface to use DHCP. See network interface dhcp.

After you complete the above steps, network connectivity to the appliance is restored and any remaining interfaces that are configured do not have a default route set.

Release 7.7.0 Valid Update Paths

You can update the Luna Network HSM appliance software to version 7.7.0 from the following previous versions:

>7.0.0, 7.1.0, 7.2.0, 7.2.2, 7.3.0, 7.3.1, 7.3.3, 7.3.4, 7.4.0, 7.4.1, 7.4.2