system hsm partition
Use this command to configure and map database information for the cryptographic storage partition assigned to the FortiWeb Luna HSM client. These parameters establish how the appliance locates, authenticates, and connects to an isolated hardware security module (HSM) partition workspace.
Before you can view or modify HSM configurations in the CLI or access HSM settings within the GUI, you must globally activate the backend daemons using the following command:
config server-policy setting
set hsm enable
For additional global status configurations and high-availability bundle arrays, see system hsm info. For detailed information on integrating HSM with FortiWeb, see the FortiWeb Administration Guide:
https://docs.fortinet.com/product/fortiweb/
To use this command, your administrator account’s access control profile must have either w or rw permission to the sysgrp area. For details, see Permissions.
Syntax
config system hsm partition
edit "<partition_name>"
next
end
| Variable | Description | Default |
| Enter the name of a partition that the FortiWeb HSM client is assigned to. | No default. | |
|
Enter the exact name of the target cryptographic partition as it is defined and labeled on the remote Luna HSM appliance server interface. |
No default. |
|
|
Enter the network IP address of the remote Luna HSM server hosting the designated storage partition workspace. This must match an active server target enrolled via the GUI network definitions. |
No default. |
|
|
Enter the Crypto Officer (CO) password required to authenticate access and establish a secure execution space inside the hardware partition slice. Critical Rule: This parameter is strictly read-only and immutable once committed. To change or fix a password typo, the entire partition entry object must be deleted and reconfigured. Complex strings containing special characters, such as two consecutive dollar signs ( |
No default. | |
|
Enter the unique 9 to 16 digit physical hardware serial number belonging to the target partition on the Luna HSM server. Usage Rule: This parameter is immutable once written to database storage. This field is optional for baseline configurations but is required for complex environments where duplicate partition label strings exist across different physical HSM host nodes. FortiWeb combines this serial value with the label string to accurately resolve isolated hardware slot paths. If omitted, FortiWeb automatically binds with the first discovered partition matching the label criteria. |
No default. |