Considerations When Cloning / Copying Between Domains
Extended Domain Management is about cloning/copying keys and objects (by a direct clone command, or by backup/restore, or via HA group member synchronization) between two HSM partitions that did not originally have the same security/cloning domain.
You cannot clone directly from one security/cloning domain to another, but the same outcome is securely achieved if at least one domain is shared between the sending and receiving partitions. Therefore, at least one partition in the transaction must support Extended Domain Management. The owner of that partition arranges for it to receive the single domain that the other HSM's partition supports, which then becomes one of the (maximum) three domains that Extended Domain Management supports. Additional factors determine some procedural variations.
>When both participating partitions support Extended Domain Management, either one is able to find a matching domain among the three possible domains on the cloning partner, or import one, if needed.
>When (say) Partition "A" is on an HSM with older firmware, and does not support Extended Domain Management, it cannot have a domain other than the one with which it was initialized. Therefore, Partition "B", that does support Extended Domain Management must take on the cloning domain of Partition A.
>When only one participating partition supports Extended Domain Management (Partition "B", for example), the other partition (Partition "A") is not aware of any domain other than the single one it possesses. Therefore the partition that does support Extended Domain Management (Partition "B") must make the common domain its Primary Domain. This is the only domain that the older partition is aware of, the domain with which any incoming or outgoing keys or objects will be encrypted.
>If FIPS 140 configuration is in force on the target partition (in this example, the newer firmware with Extended Domain Management and Universal Cloning), then Cloning Protocol version 1 (CPv1) is disabled due to not being FIPS compliant, and cannot be enabled. Where the other HSM is older, and does not support Universal Cloning, it cannot make use of the more modern, and compliant, CPv4.
As a workaround procedure, use a backup HSM that is initialized in the authentication method of the source partition.
Assuming, for example, a source HSM is a password-authenticated Luna Backup HSM G5, then proceed as follows:
a.Take a backup of the source G5 USB HSM partition using either a Luna Backup HSM G5 or, preferably a Luna Backup HSM 7, that is also initialized as password authenticated.
b.Add the password (text) cloning domain of the source partition (G5) to the target partition on a Luna Network HSM 7 that has FIPS 140 configuration and PED authentication. While doing so, add the -primary parameter so that the password-authentication cloning domain becomes the primary domain of the target (the Luna Network HSM 7).
c.Then restore the source partition from the password-authenticated USB backup HSM to the target partition (with "password" text cloning domain set as primary) located on the PED-authenticated network HSM.
Similarly, you could migrate crypto material from a password-authenticated Luna SA 6 HSM partition to a PED-authenticated partition on a Luna Network HSM 7, either indirectly via a Backup HSM, or directly such as making the Luna SA 6 partition a temporary member of an HA group along with the Luna Network HSM 7 partition -- subject to the FIPS configuration of the target, etc.
Multifactor Quorum (PED-auth) to password-auth
Going from a PED-authenticated, older, source HSM (no Extended Domain Management and no Universal Cloning) to a password-authenticated Luna Network HSM 7 as the target can be more involved. There is no ability to remotely set a an RPV (orange PED iKey), on a remotely located Luna Network HSM 7, to set up a Remote PED connection (for adding a domain or cloning keys and objects), and it would be very inconvenient to later dispatch a technician with a PED to the datacenter.A PW-authenticated HSM can receive a Multifactor Quorum (PED-auth) domain, but it requires that the PED be directly, physically connected to the Luna Network HSM, thus you would want to add the cloning domain locally, before deploying the Luna Network HSM 7 appliance to a distant datacenter. Delete this text and replace it with your own content.