80 Sun Crypto Accelerator 4000 Board Installation and User’s Guide May 2003
Zeroizing a Sun Crypto Accelerator 4000 Board
In some situations, it might be necessary to clear a board of all its key material. This
can be done using two methods. The first method is with a hardwarejumper; this
form of zeroizing will return the Sun Crypto Accelerator 4000 board to its original
factory state (failsafe mode). See “Zeroizing the Sun Crypto Accelerator 4000
Hardware to the Factory State” on page163. The second method is to use the
zeroize command.
Note – The zeroize command only removes the key material, and leaves any
updated firmware intact. This command also logs the security officerout upon
successful completion.
Tozeroize a board with the zeroize command, enter the following:
Using the vcaadm diagnostics Command
Diagnostics can be run from the vcaadm utility in addition to SunVTS. The
diagnostics command in vcaadm covers three major categories in the Sun Crypto
Accelerator 4000 hardware: general hardware,cryptographic subsystem, and
network subsystem. Testsfor general hardware cover DRAM, flash memory, the PCI
vcaadm{vcaN@hostname,sec_officer}> zeroize
WARNING: Issuing this command will zeroize all keys
on the board. Once zeroized, these keys
cannot be recovered unless you have
previously backed up your master key.
Proceed with zeroize? (Y/Yes/N/No) [No]: y
All keys zeroized successfully.