PingAccess

Adding a Thales Luna provider

Add a Thales Luna (formerly Safenet Luna) provider to begin using hardware security module (HSM)-stored key pairs in PingAccess.

Before you begin

  • Configure your HSM.

  • Configure a Luna client on the PingAccess system. The PingAccess service must have full permissions over the client.

  • Move the appropriate Luna Client library to the deploy directory on the PingAccess system.

    Choose from:

    • Windows: Move the C:\Program Files\SafeNet\LunaClient\cryptoki.dll library.

    • Linux: Move the /usr/safenet/lunaclient/lib/libCryptoki2_64.so library.

Steps

  1. Click Security, then go to HSM Providers.

  2. Click Add HSM Provider.

  3. In the Name field, enter a name for the HSM provider.

  4. In the Type list, select Thales Luna Provider.

  5. In the Slot ID field, enter the slot ID of the HSM slot to use.

  6. In the Library field, enter the name of the library you copied from the Luna client to the deploy directory.

  7. In the Password field, enter a password for connecting to the HSM provider.

  8. Click Save.

  9. Restart PingAccess.