2.14 Configuring the master keys

You must provide the information required for the MyID Installation Assistant to run the GenMaster utility to set up your master keys.

Note: If the generation of master keys fails during the installation, you can run the utility as a standalone program to set your master keys; see section 8.5, Using GenMaster.

To provide details for the master keys:

  1. Select one of the following options:

    • New Installation – Application Tier – select this option if you are installing the primary (or only) application server.

    • Existing Installation – Additional Application Tier – select this option if you have already installed MyID on your primary application server, and are now installing MyID on an additional application server.

      See section 2.14.1, Configuring the master keys for an additional application server.

    • Existing Installation – Upgrade Application Tier – select this option if you have already installed MyID and are upgrading your system.

      Because your server is already configured, you do not need to set up your master keys, and can proceed to the next stage.

  2. Click Next.

  3. Select the protection device from the drop-down list.

    You can choose from the following:

    • Registry Key Protection – the key is stored in the registry of the MyID application server.

    • Thales LUNA HSM – the key is generated and stored in the Thales Luna HSM.

    • Entrust nShield HSM – the key is generated and stored in the Entrust nShield HSM.

  4. Click Next to move to the next stage.

2.14.1 Configuring the master keys for an additional application server

If you have already installed MyID on your primary application server, and are now installing MyID on an additional application server, you do not need to create new keys; you can import the keys from your primary application server, then inform the MyID Installation Assistant, which then checks that the keys are in the correct place.

For detailed information about installing additional application servers, including importing the keys from one server to another, see the Multiple application servers section in the Advanced Configuration Guide.

To configure the master keys for an additional application server:

  1. From the Select the installation type drop-down list, select Existing Installation - Additional Application Tier and click Next.

  2. From the drop-down list, select one of the following options:

    • Windows Registry – select this option if you created the master keys in the registry on the primary application server.

    • Hardware Security Module – Set HSM PIN – select this option if you created the master keys on an HSM when you installed the primary application server.

  3. Click Next.

    If you are using an HSM, the PIN screen appears:

    Type and confirm the PIN, then click Next.