To set up a Thales ProtectServer HSM to work with OneSpan Authentication Server, you need to configure the following components:
Software
The following software must be installed on the HSM:
Thales ProtectServer firmware version 7.03.01 or later
Administrator account
The setup process requires administrative privileges in at least one administration token and one user token on the HSM.
Functionality module (FM)
Setting up a Thales ProtectServer HSM involves copying the Authentication Suite Server SDK functionality module file aal2sdk to the machine which will be used for HSM administration. The Authentication Suite Server SDK functionality module file may be unsigned or signed, depending on your requirements. OneSpan provides both a signed and an unsigned Authentication Suite Server SDK functionality module (see Installing a Thales ProtectServer hardware security module ).
HSM usage limitations
Deployments of OneSpan Authentication Server with Thales ProtectServer HSM only support HSM devices that run in normal mode, i.e.,
ET_PTKC_GENERAL_LIBRARY_MODEmust be set to NORMAL. When the HSM is run in High Availability or Workload Distribution mode, the installation of OneSpan Authentication Server will fail.