> For the complete documentation index, see [llms.txt](https://docs.keeper.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.keeper.io/sso-connect-on-prem/jp/integration-with-gemalto-hsm.md).

# Gemalto HSMとの統合

オンプレミスおよびクラウドベースのGemalto HSMによるKeeperオンプレミスSSOコネクトの鍵の保護と保管

## Gemalto HSMとの統合

![](https://2257682436-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FpnnyqlSSLL0TJdycg6le%2Fuploads%2F0N2r4bxdktgiwawAFqfn%2Fhsm.jpg?alt=media\&token=477787a4-82af-4d67-9d25-32e99ac7bdc6)

## Keeper SSOコネクトHSMの概要

SSOコネクトの `data` フォルダ内には、いくつかのファイルがあります。このうち2つのファイルには、サーバーで生成された秘密鍵が含まれています。これらの鍵は保護が必要で、エンドユーザーの自動生成マスターパスワードの暗号化と復号に使用します。また、暗号化データのローカルキャッシュを含む `.sql` ファイルもあります。この `data` フォルダへのアクセス制限が重要です。

Windows以外のマシンでは、 `data` フォルダはSSOコネクトのインストールフォルダ (通常は `$HOME/sso_connect/data`) の下にあります。

Windowsマシンでは、バージョン14.1以降、 `data` フォルダは `C:\ProgramData\Keeper SSO Connect\data\` にあります。バージョン14.1より前は、 `C:\Program Files\Keeper Security\SSO Connect\data\` にありました。

以下のとおり、HSM (ハードウェアセキュリティモジュール) を利用すると、セキュリティをさらに強化できます。HSMを利用できる場合、SSOコネクトのインスタンスごとに暗号鍵が生成され、HSMに安全に保存されます。この暗号鍵は、 `data/` フォルダ内の重要なプロパティファイルの暗号化に使用します。

## Gemalto Luna HSMの手順

### HSMの要件

1. Gemalto HSMは、Lunaファームウェア6.2以降である必要があります。

### ネットワーク要件

* TCP/443ポートの開放、Keeper SSOコネクトからwww\.keepersecurity.comへのステートフルな発信
* TCP/22ポートの開放、HSM管理端末からHSMシステムへのステートフルな発信
* TCP/22ポートの開放、CLI設定用のKeeper SSOコネクトサーバーへの着信
* TCP/1792ポートの開放、HSMシステムとの双方向通信
* TCP/8080ポートの開放、管理者GUIにアクセスするためのKeeper管理者ワークステーションからKeeper SSOコネクトへの着信 (オプション)

### ネットワークアクセスのテスト

```
$ telnet www.keepersecurity.com 443
Trying 52.204.60.27
Connected to www.keepersecurity.com.
Escape character is '^]'.

$ telnet push.services.keepersecurity.com 443
Trying 52.44.0.141...
Connected to push.services.keepersecurity.com.
Escape character is '^]'.

$ ssh <ip address of the HSM>
password: <admin-password>
```

### Linux固有の要件

CentOS 6または7を推奨しますが、以下のパッケージを追加すればUbuntuでも実行できます。

```
UBUNTU only:
$ sudo apt-get install zip unzip # used by the Luna installer
$ sudo apt-get install alien # used by the Luna installer to convert .rpm files
$ sudo apt-get install gcc-multilib # Because some Luna programs are 32-bit
```

`/lib/ld-linux.so.2` が存在する場合は、以下のセクションに進みます。

```
If /lib/ld-linux.so.2 doesn't exist:
 if /usr/lib/ld-linux.so.2 exists:
 $ sudo ln -s /usr/lib/ld-linux.so.2 /lib/ld-linux.so.2
 if /lib32/ld-linux.so.2 exists:
 $ sudo ln -s /lib32/ld-linux.so.2 /lib/ld-linux.so.2
 otherwise (Ubuntu):
 $ sudo yum install gcc-multilib # use yum or apt-get

If you are on Red Hat (CentOS), do this:
 $ sudo yum install glibc-devel.i686
```

### Lunaクライアントのインストール

Luna HSMを使用する前に、Lunaクライアントをインストールして正しく設定する必要があります。

* LunaクライアントソフトウェアをSSOコネクトサーバーにコピーします。通常、ファイル名は `LunaClient_7.3.0-165_Linux.tar.gz` のようになっています。
* SSOコネクトサーバーにログインします。
* Lunaクライアントのインストーラーを実行します。

```
$ tar xzf LunaClient_7.3.0-165.Linux.tar.gz
$ cd LunaClient_7.3.0-165_Linux/64
$ sudo sh install.sh
- Select Luna Network HSM
- Select (N)ext
- Select Luna JSP (Java)
- Select (I)nstall

$ sudo gpasswd --add <username> hsmusers
- type 'groups' to verify group membership
- You might need to create a new shell to recognize the new group

You might want to add this useful alias to your "~/.bash_profile" file.
alias luna='sudo /usr/safenet/lunaclient/bin/lunacm'
```

* `$JAVA_HOME/jre/lib/security/java.security` を編集します。
  1. セキュリティプロバイダの一覧を見つけます。
  2. `security.provider.10=com.safenetinc.luna.provider.LunaProvider` を追加します。
  3. ファイルを保存します。

### Lunaアクセスの設定

#### 要件

1. HSMマシンのIPアドレスまたはホスト名
2. 管理者パスワード (セキュリティオフィサーのパスワード)
3. 現在使用中のマシンのIPアドレスやユーザー名などの一意の文字列
4. パーティションのクリプトオフィサーのパスワード
5. 鍵を保管するパーティション名 (設定済みであること)

{% hint style="info" icon="pencil-line" %}
パーティションをまだ設定していない場合は、 `lunash` プログラムを使用し、管理者としてログインしてパーティションを作成してください。Gemalto Lunaのドキュメントをご参照ください。
{% endhint %}

#### HSM設定の確認

1. Lunaクライアントを起動します。

```
$ luna
lunacm (64-bit) v7.3.0-165. Copyright (c) 2018 SafeNet. All rights reserved.

lunacm:> clientconfig deploy -n <hsm-ip-address> -c <unique-string> -par <partition-name> -ur admin -pw <hsm-admin-password> -v

... make sure it finishes successfully


Available HSMs:

Slot Id -> 0 
Label -> [your-partition-name]
Serial Number -> 12345678987654321
Model -> LunaSA 7.3.0 
Firmware Version -> 7.3.0 
Configuration -> Luna User Partition With SO (PW) Key Export With Cloning Mode
Slot Description -> Net Token Slot


Current Slot Id: 0


lunacm:>role login -n co
enter password: crypto-officer-password

Command Result : No Error

lunacm:>par con # display contents of partition
lunacm:>exit
```

### Keeper SSOコネクトのHSMアクセス設定

通常のSSOコネクト設定の質問に加えて、以下のようなHSM固有の質問があります。

```
$ java -jar SSOConnect.jar -config

... normal SSO Connect configuration questions...

Configure Secure Key Storage (y/N): y
IMPORTANT: Make sure that this server is already connected to a networked HSM or other secure key storage device.
Type of Secure Key Storage (Gemalto SafeNet Luna HSM): <return>
Secure storage device access parameters (slot,password): <return>
 slot: 0
 password: crypto-officer-password
A certificate chain is required in order to store an encryption key.
You may use the SSL certificate file entered previously, or use a different one.
Certificate chain file (/home/ubuntu/keeperSSO/data/sso_keystore.jks): <return>
Certificate chain file password (none): <return>
1 certificates found
Enable Secure Key Storage (Y/n): y
```

### トラブルシューティング

#### 設定のトラブルシューティング

1. サーバーが要件を満たしていることを確認します。CentOS 6または7を推奨します。現時点ではWindowsは対象外です。

```
$ rpm -q centos-release
centos-release-7-6.1810.2.el7.centos.x86_64

$ cat /etc/centos-release
CentOS Linux release 7.6.1810 (Core)
```

2. Lunaクライアントがサーバーに正しくインストールされていることを確認します。Lunaクライアントを実行してクリプトオフィサーとしてログインし、パーティションの内容を表示できることを確認します。

```
$ sudo /usr/safenet/lunaclient/bin/lunacm

luna> role login -n co
(enter password)
luna> par con
If this HSM has been used with Keeper before, there will be an existing key with a name like Keeper SSO Properties 514320201573
```

3. Java 1.8またはJava 11が利用できることを確認します。

```
$ java -version
java version "1.8.0_201"
Java(TM) SE Runtime Environment (build 1.8.0_201-b09)
Java HotSpot(TM) 64-Bit Server VM (build 25.201-b09, mixed mode)
```

4. Lunaライブラリが利用できることを確認します。

```
$ ls sso_connect/*Luna*
libLunaAPI.so LunaProvider.jar
```

5. 正しいポートが開放されていることを確認します。ファイアウォールは、ポート22および1792で発着信両方の接続を許可する必要があります。

```
If the firewall is local, use:
$ iptables -xvn -L
```

6. ユーザーがhsmusersグループのメンバーであることを確認します。

```
$ whoami
centos

$ groups
centos adm wheel systemd-journal hsmusers

** The Luna software requires that the user accessing the Luna libraries be a member of the hsmusers group.
$ sudo gpasswd --add centos hsmusers
You will need to open a new shell to see that this command worked correctly.
```

7. SSOコネクトがマシンにインストールされていることを確認します。
   * 通常、 `sso_connect` 、 `KeeperSSO` など、多数のjarファイルを含むフォルダ
8. `data` フォルダに不完全な設定がないことを確認します。
   * 以前SSOコネクトの設定に失敗している場合は、 `KeeperSSO/data` フォルダを削除してやり直すのが安全です。
9. アプリが `data/` フォルダに対する読み取り/書き込み権限を持っていることを確認します。

```
$ ls -ld data
drwxrwxr-x 2 centos centos 181 Feb 4 19:42 data
```

#### 動作のトラブルシューティング

1. ログファイルにエラーがないか確認します。SSOコネクトのセキュアキーストレージサブシステムは、問題が発生すると、ログにERROR行を出力します。

```
$ more logs/ssoconnect.log
```

2. エラーは `Unable to use Secure Key Storage` のバリエーションになります。これは、以下のいずれかの問題を示しています。

```
a. Network problem accessing the HSM
- Perform Step 2 of "Troubleshooting the Configuration" to verify access to the HSM.

b. data/sks.properties is missing
- if data/sks.properties is missing you will need to re-configure SSOConnect.

c. The encrypted property files are missing
- Check for data/instance.encp and data/shared.encp.

d. The encryption key is missing from the HSM
- Did somebody clear the HSM partition? You will need to re-configure SSOConnect.

e. The server may be out of disk space
- clear some disk space.

f. The encryption algorithm used is not supported on the HSM
- The algorithm is AES/GCM/NoPadding. Check with the device provider.

g. The file data/sso-keystore.jks is missing
- The program cannot store a key in the HSM without the certificate chain from the sso_keystore.jks file.
Find the file and ensure that it is in the data folder.
```

## バックアップ

`data` フォルダにはSSOコネクトの設定ファイルが含まれています。少なくとも、初回設定の直後と、設定を変更するたびにバックアップしてください。設定ファイル以外にも、 `data` にはデータファイルがありますが、Keeperサーバーと同期が取れなくなった場合は自動的に更新されます。そのため、定期バックアップを利用しても構いませんが、必須ではありません。設定のすべてがインスタンス間で共有されるわけではないため、SSOコネクトの各インスタンスで `data` フォルダを個別にバックアップする必要があります。

Windows以外のマシンでは、 `data` フォルダはSSOコネクトのインストールフォルダ (通常は `$HOME/sso_connect/data`) の下にあります。

Windowsマシンでは、バージョン14.1以降、 `data` フォルダは `C:\ProgramData\Keeper SSO Connect\data\` にあります。バージョン14.1より前は、 `C:\Program Files\Keeper Security\SSO Connect\data\` にありました。

## 回復

### サーバーの障害

SSOコネクトサーバーで障害が発生した場合は、上記の標準的なインストール手順に従って、代替マシンにLunaとSSOコネクトを再インストールする必要があります。

上記のとおり `data` フォルダをバックアップしている場合は、SSOコネクトを起動する前に復元してください。 (SSOコネクトを起動したため) `data` フォルダがすでに存在する場合は、SSOコネクトを停止し、データフォルダ内のファイルをすべて削除し、バックアップしたデータフォルダからファイルをコピーして、SSOコネクトを再起動します。SSOコネクトが正常に起動するはずです。

`data` フォルダをバックアップしていなかった場合、またはバックアップが古い場合は、新規インストールと同様に代替インスタンスを設定する必要があります。SSOコネクトのインストールガイドに従ってください。

### HSMの障害

HSMを使用する場合、HSMには `data` フォルダ内の設定ファイルの復号に使用する暗号鍵が保存されます。HSMへのアクセスは、SSOコネクトの起動時に1回と、設定変更時に行われます。設定ファイルが暗号化されており、HSMに保存した暗号鍵が失われたか、アクセスできない場合は、暗号化されていない設定ファイルを新規作成するために、SSOコネクトインスタンスを再度設定する必要があります。 `data` フォルダの内容を削除し、SSOコネクトをもう一度最初から設定します。

HSM/SKSの使用を無効にするには、「Enable SKS?」という設定の質問に `no` と入力するか、 `-disableSKS` コマンドラインオプションを使用します。


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.keeper.io/sso-connect-on-prem/jp/integration-with-gemalto-hsm.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
