Upload the Authentication Suite Server SDK FM module

Prev Next

Before you can use Authentication Suite Server SDK for Thales ProtectServer HSM, you need to upload the Authentication Suite Server SDK FM module to the HSM.

The Authentication Suite Server SDK for HSM package contains an unsigned and a signed FM module binary file for the following:

  • Thales ProtectServer 3 HSM devices (k7-ppc processor)
  • ProtectServer 2 HSM devices (k6-ppc processor)
  • ProtectServer HSM devices (k5-arm processor)

You can choose from the following options:

  • Use the unsigned FM module (aal2sdk) located in one of the following folders (depending on the Thales ProtectServerHSM model version):

    • INSTALL_DIR/hsm/k7-ppc/unsigned
    • INSTALL_DIR/hsm/k6-ppc/unsigned
    • INSTALL_DIR/hsm/k5-arm/unsigned

    In this case, you need to generate your own self-signed certificate to sign the module before it is uploaded to the HSM.

  • Use the signed FM module (aal2sdk.signed) located in one of the following folders (depending on the Thales ProtectServerHSM model version):

    • INSTALL_DIR/hsm/k7-ppc/signed
    • INSTALL_DIR/hsm/k6-ppc/signed
    • INSTALL_DIR/hsm/k5-arm/signed

    These modules are signed by OneSpan. The corresponding OneSpan code signing certificate (vascosigningcert_20470309.crt) is required to upload the module.

Firmware versions

The Authentication Suite Server SDK FM modules for Thales ProtectServer 3 (k7-ppc) require Thales ProtectServer firmware version 7.02.00 or later in the HSM.

The Authentication Suite Server SDK FM modules for Thales ProtectServer 2 (k6-ppc) require Thales ProtectServer firmware version 5.00.02 or later in the HSM.

The Authentication Suite Server SDK FM modules for SafeNet ProtectServer (k5-arm) require Thales ProtectServer firmware version 2.01.00 or later in the HSM.