Install a PCIe HSM

This guide covers the following HSMs:

  • nShield Solo XC

  • nShield 5s

If you encounter any problems during the install process, refer to HSM Status indicators (nShield Solo and Solo XC) and Morse code error messages (nShield Solo and Solo XC), or HSM status indicators and error codes (nShield 5s). These pages explain the status LED messages, and provide other information.

Module pre-installation steps

Check the module to ensure that there is no sign of damage or tampering:

  • Check the epoxy resin security coating, or the metal lid for the Solo XC, for obvious signs of damage.

  • If you intend to install the module with an external smart card reader, check the cable for signs of tampering. If evidence of tampering is present, do not use and request a new cable.

  • nShield Solo and Solo XC: Check that the physical switches are in the required positions. See the diagram in the Module back panel section for switch labelling.

    • To use the remote mode switch override to change the mode, the physical mode switch (C) must be set to Operational (O).

    • To use the Remote Administration feature to change the mode of the module remotely, ensure that the jumper switch (E) is in the off position and the physical mode switch (C) is set to Operational (O).
      The default factory setting of the jumper DIP switch E is Off. This enables remote MOI switching. Factory shipping nShield Solo HSMs loaded with firmware 2.61.2 or greater will support remote MOI switching by default. Customers who expressly do not want to enable the remote MOI switching capability must switch jump switch E to the On position.

    • To deactivate the physical mode switch (C), change jumper switch D to the On position.

Module back panel

solo card details
Label Description

A

Status LED

B

Recessed clear button (Solo and Solo XC) or recovery mode button (5s)

C

Physical mode switch

D

Physical mode override jumper switch, in the Off position. When set to On, the mode switch (C) is deactivated. See the Checking and changing the mode on an nShield Solo module for more information.

E

Remote mode override jumper switch, in the Off position. When set to On, remote mode switching is disabled. See Checking and changing the mode on an nShield Solo module for more information.

F

A mini-DIN connector for connecting a smart card reader.

The configuration of connectors varies between modules and might not be as in the image. The nShield 5s does not contain physical switches.

Swap the module bracket

If the fitted module bracket is not the same height as the slot, swap it for the correct size. Both full height and low profile brackets are supplied with the module.

Do not touch the connector pins, or the exposed area of the module without taking electrostatic discharge (ESD) precautions.

To fit the bracket to the module:

  1. Remove the two screws from the solder side of the module.

  2. Remove the incorrect bracket.

  3. Fit the correct bracket to the component side of the module.

  4. Insert the two screws into the solder side of the module to secure the bracket. Do not over tighten the screws.

change panel nshield5s
Figure 1. Screw placement on an nShield 5s.
Screw placement is the same on a Solo module bracket, however the Solo and Solo XC brackets also have a physical mode switch.

Install the module

  1. Power off the system and while taking electrostatic discharge precautions, remove the module from its packaging.

  2. Open the computer case and locate an empty PCIe slot. If necessary, follow the instructions that your computer manufacturer supplied.

    You must only install the HSM into a PCIe x4 slot, unless you are installing an nShield Solo (non-XC variant), which can use a PCIe x1 slot. See the instructions that your computer manufacturer supplied to correctly identify the slots on your computer.
  3. If there is a blanking plate across the opening to the outside of the computer, remove it. Check that the opening is large enough to enable you to access the module back panel.

  4. Insert the contact edge of the module into the empty slot. Press the card firmly into the connector to ensure that:

    • The contacts are fully inserted in the connector

    • The back panel is correctly aligned with the access slot in the chassis

  5. Use the bracket screw or fixing clip to secure the module to the computer chassis.

  6. (Solo XC only) Check that the two jumper switches on the module are still in required positions (see Back panel and jumper switches).

  7. (Solo XC only) Check that the mode switch is still in the center O (operational) position.

  8. Replace the computer case.

Fitting a smart card reader

Connect the smart card reader to the connector on the back panel of the module. A D-type to mini-DIN adapter cable is supplied with the module.

After installing the module

Set the system clock nShield 5s only

Set the system clock. See Setting the system clock.

Install the nShield World software

If the Security World software has not already been installed, you must install the Security World Software by following the instructions in the nShield Security World Software v13.6.5 Installation Guide.

Although methods of installation vary from platform to platform, the Security World Software should automatically detect the module on your computer and install the drivers. You do not have to restart the system.

nShield 5s only

If this is not the first HSM installed in this host, the Security World software is already installed. However, you still need to set up communication between the host and the newly installed module. The module must either be in factory state or have been previously prepared for use on this host. For more information, see Set up communication between host and module (nShield 5s HSMs).

If the new module has been supplied from the factory it will already be in factory state.