HSM status indicators and error codes (nShield 5s)
This guide covers the following HSMs:
-
nShield 5s
The Entrust nShield 5s HSM is fitted with a tri-color LED on the back panel. This LED indicates the operational or error state of the HSM, see LED status.
Errors associated with the nCore API service are reported separately, and do not generally result in an unrecoverable error state. These are described at Error codes from the nCore API service.
LED status
The following states indicate a normal operational state:
| Colour | Pattern | Meaning |
|---|---|---|
N/A |
Blank |
No power or processors not working. |
Green |
Solid |
Power is good. Main processor has not started booting. |
Cyan |
Solid |
Main processor is booting. |
Cyan/Blue |
Slow flash |
Board support processor firmware upgrade in progress. |
Blue |
Solid |
System has booted, now idle. |
Blue |
Flickering |
System is active - normal operation. |
The following states indicate an error within the HSM:
| Colour | Pattern | Meaning |
|---|---|---|
Blue |
Error code |
Error state for when the HSM is in an unrecoverable state, see LED error states for more information. |
Red |
Error code |
Error state for when the HSM is in an unrecoverable state see LED error states for more information. |
Red |
Fast flash |
Board support processor bootloader failure. |
Blue/Red |
Flash |
Board support processor detected a tamper condition. |
Other |
Any |
Contact Entrust Support. |
LED error states
If the Entrust nShield 5s HSM encounters an unrecoverable error, it enters an error state. In an error state, the HSM does not respond to commands and does not write data to the bus. The LED displays a repeating flashing pattern, similar to 'beep codes' from a PC BIOS, to indicate specific error state. These are listed under Error codes shown on the LED.
In some cases you can reset an HSM in an error state by powering down the HSM and then reapplying power, or with hsmadmin reset.
Not all errors can be reset in this way.
If any HSM goes into an error state, contact Entrust Support, and give full details of your HSM set-up and the error code.
Entrust recommends that you contact Entrust Support even if you successfully recover from the error.
For troubleshooting information, see Troubleshooting 5s.
Error codes shown on the LED
If an HSM enters an error state, the LED flashes with a BIOS-style pattern to indicate an error code.
All the LED error codes have three digits:
-
The first digit is indicated by between one and five short flashes.
-
The second digit is then indicated by one to five long flashes. Long flashes are approximately three times the duration of the short flashes.
-
The third digit is then indicated by one to five short flashes.
There is then a longer gap and the error code repeats.
| Colour | Digits | Meaning |
|---|---|---|
Red |
1-1-1 |
Battery voltage out of spec. See Battery replacement |
Red |
1-2-1 |
Internal voltage rail (Crypto SerDes core) out of spec |
Red |
1-2-2 |
Internal voltage rail (main CPU SerDes core) out of spec |
Red |
1-2-3 |
Internal voltage rail (main CPU core) out of spec |
Red |
1-2-4 |
Internal voltage rail (main CPU SerDes IO) out of spec |
Red |
1-2-5 |
Internal voltage rail (Crypto SerDes IO) voltage out of spec |
Red |
1-3-1 |
Internal voltage rail (main CPU IFC IO) out of spec |
Red |
1-3-2 |
Internal voltage rail (DDR access) out of spec |
Red |
1-3-3 |
Internal voltage rail (DDR IO) out of spec |
Red |
1-3-4 |
Internal voltage rail (12V) out of spec |
Red |
1-3-5 |
Internal voltage rail (Board support processor) out of spec |
Red |
1-5-1 |
Temperature out of spec (Board support processor) |
Red |
1-5-2 |
Temperature out of spec (main CPU) |
Red |
1-5-3 |
Temperature out of spec (Crypto) |
Red |
1-5-4 |
Board support processor app blank |
Red |
1-5-5 |
Board support processor app invalid |
Red |
2-1-1 |
Board support processor secure state corrupted |
Red |
2-1-2 |
No bootloader heartbeat |
Red |
2-1-3 |
Board-ID PROM failed |
Blue |
2-1-5 |
Firmware signature auth failure |
Red |
2-2-2 |
Crypto known-answer tests failed |
Red |
2-2-3 |
RNG hardware failed |
Red |
2-2-4 |
FIPS DRBG failed |
Red |
2-2-5 |
OpenSSL self-test failed |
Red |
2-3-1 |
OpenSSH self-test failed |
Red |
2-3-2 |
Library signature verification failed |
Red |
2-3-3 |
Crypto initialisation failed |
Red |
2-3-4 |
Init script failed |
Red |
2-3-5 |
Error during error handling |
Red |
2-5-1 |
Error playing LED sequence |
Red |
2-5-2 |
Run-level monitor failed |
Red |
2-5-3 |
Board Support Processor interface failed |
Red |
2-5-4 |
Environment monitor failed |
Red |
2-5-5 |
System log space is critically low |
Red |
3-1-1 |
Uboot PCIe PLL lock failed |
Red |
3-1-2 |
Uboot DDR init failed |
Red |
3-1-5 |
Uboot handshake failed |
Error codes from the nCore API service
In the nShield 5s HSM, the nCore API service runs as a separate, sandboxed process. Errors arising within this process do not trigger an unrecoverable error state, and do not display an LED error code.
Instead, you can retrieve an error codes using the enquiry utility, and restart the nCore API
service with the nopclearfail utility. Error codes appear in the hardware status field of the
enquiry output, and are included in the hardserver log.
Other than the Cmd_Fail error code (SOS D), there are no circumstances which intentionally
result in an nCore API service error. Please contact Entrust Support if you encounter
such an error.
|
nCore API service error code list
Error codes are 'SOS' followed by two or more letters. These are listed in the table below.
| Code | Meaning |
|---|---|
D |
|
H C |
Initialization failed (job dispatch) |
H C P |
Initialization failed (poll thread) |
H C X |
Initialization failed (offload selftest) |
H C 0 xxx |
Known-answer test failed ( |
H D |
Initialization failed (system info) |
H E |
Initialization failed (setting mode) |
H F |
Initialization failed (crypto offload) |
H H H |
Initialization failed (host interface startup) |
H J T |
Initialization failed (job threads) |
H M Z |
Crypto offload driver failed |
H M |
Initialization failed (early startup) |
H O |
Initialization failed (token interface) |
H O B |
Initialization failed (DES3 offload) |
H O C |
Initialization failed (AES offload) |
H R |
Runtime RNG failure |
H R S |
Initialization failed (RNG) |
H R F O |
Online FIPS RNG test failed |
H S |
Initialization failed (host interface) |
H S C |
SOS file check failed |
O L C |
Assertion failure or |
O L E |
Access violation |
O L J |
Arithmetic exception |
O L M |
Illegal instruction |
O L L |
Unknown signal raised |