8.5 Using GenMaster

SIU references: SIU-267, SIU-268, SIU-283, SIU-284, SIU-285, SIU-286.

The GenMaster application allows you to do the following:

Your choice of key protection mechanism is a compromise between cost, convenience and security.

8.5.1 Running GenMaster

The GenMaster program is started automatically by the installation process. You can also start the program from the Start menu.

  1. Run GenMaster.

  2. If prompted, enter an admin user name and password.

    The Welcome screen appears.

    GenMaster 01

  3. Click Next.
  4. Select the method of securing the master keys.

    GenMaster 02

    Note: The master key is an AES256 key.

    Select one of the following options:

    • Registry Key Protection – the key is stored in the registry of the MyID application server.
    • nCipher HSM key protection – the key is generated and stored in the nShield HSM.

      Note: Entrust nShield HSMs were previously known as nCipher nShield.

    • LUNA SA HSM key protection – the key is generated and stored in the Thales Luna HSM.

    Note: Entrust nShield and SafeNet Network (LUNA) HSMs are currently supported. Make sure you have set up your HSM according to the instructions in the relevant integration guide before installing MyID:

    If an HSM is not installed, a corresponding entry will not be displayed in the drop-down list.

    If an HSM is installed and the corresponding entry is not in the drop-down list, then review the instructions in the relevant integration guide and ensure all steps have been followed.

    In particular, for the nCipher HSM, check that the CknFast.DLL has been copied into the Windows\System32 directory.

  5. Set up the key protection.

  6. You can now select one of the following options:

    • Configure Secret Keys – this option allows you to set up secret keys that allow other applications to share sensitive data.
    • Configure startup password – this option allows you to set the password for the startup user account.

      Note: You must set up a password for this account when you first install MyID or you will be unable to access the system. If you are upgrading an existing MyID system and already have a smart card or password user that you can use to access the system, you do not have to configure a startup password.

    GenMaster 04

  7. To configure secret keys:

    1. Select Configure Secret Keys.
    2. Click Next.

      Create Secret Key

    3. Enter the Name and Description.
    4. Click Generate.

      This will populate the Hexed Symmetric Key box.

    5. Click Next to continue.

      Confirm Secret Key

    6. Click Next to confirm the details of the shared secret key.
  8. To set the startup user password:

    Note: If you have upgraded from an earlier version of MyID, or have removed the startup account as part of locking down the installation, the startup user does not exist, and you will be unable to configure the startup password. If you need to recover this startup user account, you can use the Recover Startup User utility; see the Recover Startup User section in the Implementation Guide.

    1. Select Configure startup password.
    2. Click Next.

      Enter startup Password

    3. Type the password, and type it again to confirm it.
    4. Click Next.

      GenMaster 06

    Note: If you enter the startup user password incorrectly three times, the startup user account becomes locked. To unlock the startup user account, run GenMaster again, and create a new password for the startup user.

  9. Click Finish.

If you are running GenMaster as part of the initial installation, GenMaster returns control to the main MyID installation program, which completes its setup.