Enabling communication between the SMC and Security Engine

The target of evaluation uses a registration process to join Security Engines to the SMC using a registration channel. The administrator enables the Security Engine joining by saving the initial configuration in the SMC before the registration channel is established. The SMC generates a one-time password that is used as a secret in enabling process. The administrator has to take note of the one-time password and enter it on the Security Engine console to initiate the registration process. The Security Engine initiates the communication to set up the registration channel.

Preparations for the registration

  • Prepare the configuration as described in section, Preparations for the configuration.
  • Make sure that the Virtual SMC Appliance is installed in FIPS mode using 256-bit security setting according to Enable FIPS mode on the SMC Appliance.
  • Make sure that the joining Security Engine is installed in FIPS mode using the 256-bit security setting according to Install the Security Engine in FIPS mode.
  • Verify that the Virtual SMC is connected to the management network using its management network interface.
  • Verify that the joining Engine is connected to the management network using its management network interface.

The SMC and Security Engines use TLS for protected communications and X.509 certificates for mutual authentication.

When the SMC is installed, an internal ECDSA certificate authority is automatically created. The internal certificate authority issues certificates for the SMC components during the virtual SMC Appliance installation. Security Engine certificates are issued during the registration process.

A secure TLS communication channel is established for the registration. The administrator confirms or enters the expected SMC certificate SHA-512 hash for authentication. SMC authenticates the Security Engine using an SMC generated one-time password that the administrator inputs into the Engine.

During the registration process SMC sends the internal CA certificate to the Security Engine, the Security Engine generates a certificate signing request, the SMC internal CA issues a certificate that the SMC sends to the Security Engine, and the Security Engine validates the received certificate.

In the 256-bit mode ECDSA P-384 with SHA-384 digital signatures is used in all certificates for the communication between SMC and Security Engines. The reference identifiers in the SAN DNS field for subsequent TLS client and server authentication are configured automatically during the registration.

After initial contact is made, subsequent TLS connections between the components are mutually authenticated.

Recovering from a failed registration

If the registration process is interrupted or fails due to a connectivity issue, restart the process from the Save the initial configuration in the SMC Client step once connectivity has been restored.

Recovering from a failed management connection after successful registration between Security Engine and SMC

If management connectivity between the SMC and Security Engine fails after registration has been completed, follow these general steps to recover:
  • Check network connectivity between the Security Engine, SMC and CA infrastructure in use.
  • Check the SMC logs for error messages.
  • Check that none of the certificates involved has expired. To renew certificate of each component, see corresponding section in this guide:
    • Renew a certificate for the Management Server.
    • Renew a certificate for the Log Server.
    • Renew a certificate for the Security Engine.
  • Contact Forcepoint support as a last resort.