HSM status indicators and error codes (nShield 5s)

This guide covers the following HSMs:

  • nShield 5s

The Entrust nShield 5s HSM is fitted with a tri-color LED on the back panel. This LED indicates the operational or error state of the HSM, see LED status.

Errors associated with the nCore API service are reported separately, and do not generally result in an unrecoverable error state. These are described at Error codes from the nCore API service.

LED status

The following states indicate a normal operational state:

Colour Pattern Meaning

N/A

Blank

No power or processors not working.

Green

Solid

Power is good. Main processor has not started booting.

Cyan

Solid

Main processor is booting.

Cyan/Blue

Slow flash

Board support processor firmware upgrade in progress.

Blue

Solid

System has booted, now idle.

Blue

Flickering

System is active - normal operation.

The following states indicate an error within the HSM:

Colour Pattern Meaning

Blue

Error code

Error state for when the HSM is in an unrecoverable state, see LED error states for more information.

Red

Error code

Error state for when the HSM is in an unrecoverable state see LED error states for more information.

Red

Fast flash

Board support processor bootloader failure.

Blue/Red

Flash

Board support processor detected a tamper condition.

Other

Any

Contact Entrust Support.

LED error states

If the Entrust nShield 5s HSM encounters an unrecoverable error, it enters an error state. In an error state, the HSM does not respond to commands and does not write data to the bus. The LED displays a repeating flashing pattern, similar to 'beep codes' from a PC BIOS, to indicate specific error state. These are listed under Error codes shown on the LED.

In some cases you can reset an HSM in an error state by powering down the HSM and then reapplying power, or with hsmadmin reset. Not all errors can be reset in this way.

If any HSM goes into an error state, contact Entrust Support, and give full details of your HSM set-up and the error code.

Entrust recommends that you contact Entrust Support even if you successfully recover from the error.

For troubleshooting information, see Troubleshooting 5s.

Error codes shown on the LED

If an HSM enters an error state, the LED flashes with a BIOS-style pattern to indicate an error code.

All the LED error codes have three digits:

  • The first digit is indicated by between one and five short flashes.

  • The second digit is then indicated by one to five long flashes. Long flashes are approximately three times the duration of the short flashes.

  • The third digit is then indicated by one to five short flashes.

There is then a longer gap and the error code repeats.

Colour Digits Meaning

Red

1-1-1

Battery voltage out of spec. See Battery replacement

Red

1-2-1

Internal voltage rail (Crypto SerDes core) out of spec

Red

1-2-2

Internal voltage rail (main CPU SerDes core) out of spec

Red

1-2-3

Internal voltage rail (main CPU core) out of spec

Red

1-2-4

Internal voltage rail (main CPU SerDes IO) out of spec

Red

1-2-5

Internal voltage rail (Crypto SerDes IO) voltage out of spec

Red

1-3-1

Internal voltage rail (main CPU IFC IO) out of spec

Red

1-3-2

Internal voltage rail (DDR access) out of spec

Red

1-3-3

Internal voltage rail (DDR IO) out of spec

Red

1-3-4

Internal voltage rail (12V) out of spec

Red

1-3-5

Internal voltage rail (Board support processor) out of spec

Red

1-5-1

Temperature out of spec (Board support processor)

Red

1-5-2

Temperature out of spec (main CPU)

Red

1-5-3

Temperature out of spec (Crypto)

Red

1-5-4

Board support processor app blank

Red

1-5-5

Board support processor app invalid

Red

2-1-1

Board support processor secure state corrupted

Red

2-1-2

No bootloader heartbeat

Red

2-1-3

Board-ID PROM failed

Blue

2-1-5

Firmware signature auth failure

Red

2-2-2

Crypto known-answer tests failed

Red

2-2-3

RNG hardware failed

Red

2-2-4

FIPS DRBG failed

Red

2-2-5

OpenSSL self-test failed

Red

2-3-1

OpenSSH self-test failed

Red

2-3-2

Library signature verification failed

Red

2-3-3

Crypto initialisation failed

Red

2-3-4

Init script failed

Red

2-3-5

Error during error handling

Red

2-5-1

Error playing LED sequence

Red

2-5-2

Run-level monitor failed

Red

2-5-3

Board Support Processor interface failed

Red

2-5-4

Environment monitor failed

Red

2-5-5

System log space is critically low

Red

3-1-1

Uboot PCIe PLL lock failed

Red

3-1-2

Uboot DDR init failed

Red

3-1-5

Uboot handshake failed

Error codes from the nCore API service

In the nShield 5s HSM, the nCore API service runs as a separate, sandboxed process. Errors arising within this process do not trigger an unrecoverable error state, and do not display an LED error code.

Instead, you can retrieve an error codes using the enquiry utility, and restart the nCore API service with the nopclearfail utility. Error codes appear in the hardware status field of the enquiry output, and are included in the hardserver log.

Other than the Cmd_Fail error code (SOS D), there are no circumstances which intentionally result in an nCore API service error. Please contact Entrust Support if you encounter such an error.

nCore API service error code list

Error codes are 'SOS' followed by two or more letters. These are listed in the table below.

Code Meaning

D

Fail command received

H C

Initialization failed (job dispatch)

H C P

Initialization failed (poll thread)

H C X

Initialization failed (offload selftest)

H C 0 xxx

Known-answer test failed (xxx identifies algorithm)

H D

Initialization failed (system info)

H E

Initialization failed (setting mode)

H F

Initialization failed (crypto offload)

H H H

Initialization failed (host interface startup)

H J T

Initialization failed (job threads)

H M Z

Crypto offload driver failed

H M

Initialization failed (early startup)

H O

Initialization failed (token interface)

H O B

Initialization failed (DES3 offload)

H O C

Initialization failed (AES offload)

H R

Runtime RNG failure

H R S

Initialization failed (RNG)

H R F O

Online FIPS RNG test failed

H S

Initialization failed (host interface)

H S C

SOS file check failed

O L C

Assertion failure or abort() called

O L E

Access violation

O L J

Arithmetic exception

O L M

Illegal instruction

O L L

Unknown signal raised