Load LMK (LK)
Command:
LK
Function:
To load LMK components from smartcards.
Authorization:
The HSM must be in the secure state to run this command.
• Confirm remote access (if already commissioned for remote access using
Inputs:
the payShield Manager)
• LMK Identifier: 2 numeric digits.
• Optional comments
• Smartcards (RLMKs are supported) with LMK components.
• PINs for the Smartcards or passwords. The PIN must be entered within 60
seconds.
• Whether to make this LMK the Default/Management LMK - see Notes
below.
• Individual LMK component check value(s).
Outputs:
• Final LMK check value.
• For PCI HSM compliance, PINs and smartcards must be used to
Notes:
authenticate the Security Officers.
• Use of this command will always create an entry in the Audit Log.
• If there is not already a Default and/or Management LMK installed (i.e. the
LMK IDs identified in the security settings as being the default and
management LMKs are empty), you will be asked if you wish to make this
new LMK the Default/Management LMK.
• An error is returned if an attempt is made to load an LMK with a single
component where:
• Invalid LMK identifier - no LMK loaded or entered identifier out of range.
Errors:
• Load failed check comparison - card is blank.
• Not a LMK card - card is not formatted for LMK or key storage.
• Card not formatted - card is not formatted.
• Smartcard error; command/return: 0003 - invalid PIN is entered.
• Invalid PIN; re-enter - a PIN of less than 5 or greater than 8 digits is
entered.
• Invalid key – a standard Thales test key cannot be given live status.
• Incompatible key status – the components have different status ("live" or
"test").
• Invalid key - Multiple key components required – an attempt has been
made to load an LMK (other than a test LMK) using a single component
when the security setting to enforce multiple components has been set to
YES.
©Thales Group
All Rights Reserved
payShield 10K Installation and User Guide
The LMK is not a test LMK, and
o
The security setting to enforce multiple key components has
o
been set to YES.
Variant
Key Block
Online
Offline
Authorization: Not required
Secure
Page 297
Need help?
Do you have a question about the payShield 10K and is the answer not in the manual?
Questions and answers
how to clear error alert in Thales HSM 9000?
To clear an error alert in Thales payShield 10K:
1. Navigate to Status > Maintenance in the system interface.
2. Click On to activate maintenance mode.
3. The handle light on payShield 10K should turn blue, indicating maintenance mode is active.
Additionally, if the security setting "Allow Error light to be extinguished when viewing Error Log?" is set to YES, viewing the error log may also clear the error light.
This answer is automatically generated