Layer7 API Management

  • 1.  What to install for thales nshield connect

    Posted Feb 24, 2017 03:49 AM

    Hello, does anyone have experience with the Thales nshield connect HSM.
    We can install the following components, but i could not find documentation on the minimal required components for the CA API gateway 9.2:

     

    This is Security World Software for nShield, version 12.10.00

    This installer contains the following software:

     

    hwsp   agg   - nShield Hardware Support (mandatory)       2.85.4cam1

    ctls   agg   - nShield Core Tools (recommended)           2.85.4cam6

    dsserv user  - nShield Remote Administration Service      0.21.1cam3

    hwcrhk user  - Crypto Hardware Interface (CHIL) plugin    1.33.1cam5

    hwcrhk gnupg - CHIL patch for The GNU Privacy Guard       1.33.1cam5

    javasp agg   - nShield Java Support (including KeySafe)   2.85.4cam7

    jcecsp user  - nCipherKM JCA/JCE provider classes         1.42.1cam7

    ncsnmp user  - nShield SNMP monitoring agent              0.36.1cam5

    nhfw   agg   - nShield Connect firmware files             2.85.4cam8

    pkcs11 user  - nShield PKCS#11 provider                   2.19.1cam9

    ratls  agg   - nShield Remote Administration Client Tools 2.85.4cam1



  • 2.  Re: What to install for thales nshield connect
    Best Answer

    Broadcom Employee
    Posted Feb 24, 2017 05:47 AM

    Hi,

     

    Please refer to the API gateway 9.2 documentation for the Thales nshield connect HSM requirement and configuration

     

    Configure Thales Hardware Security Modules - CA API Gateway - 9.2 - CA Technologies Documentation 

     

    Thanks,

    Gopinath



  • 3.  Re: What to install for thales nshield connect

    Posted Mar 23, 2017 08:02 AM

    It seems to be missing on the official documentation.

     

    Specifically we need to know which thales components are required for the CA api gateway.

    The CA wiki does not have any installation guides, the configuration is briefly explained.

     

    I found only one installation reference, checking an rpm status, on the wiki.
    I believe it is outdated however and incorrect for the current thales HSM versions.


    From the wiki : 
    Configure the nShield Connect - CA API Gateway - 9.2 - CA Technologies Documentation

    • The ssg-nshieldpci RPM is installed. You can verify this RPM by running the command:

      # rpm -qa | grep ssg-nshieldpci