Configure Guardian key label
Perform the following tasks to configure the key label on the Guardian.
Go to Identity Management > Roles, and select [ Add ] at the bottom of the page.
In the Info tab of the Role Editor window, set the role name, set the type to Application, and set the number of users required to log in (set this to 1 if you need only a single user).
In the Permissions tab, select the following permissions:
Permission
Subpermission
Keys
Export
In the Advanced tab, select Balancer in the Allowed Ports drop-down list.
Select [ OK ] to finish creating the role.
Go to Identity Management > Identities, right-click anywhere, and select Add > Client Application.
In the Info tab, set a name for the identity and leave the storage location as Application.
In the Assigned Roles tab, select the role you created in the previous section.
In the Authentication tab, select the API Key mechanism and select [ Remove ]. Select [ Add ] and configure a password for the identity. Then, select [ OK ].
Allocate the correct Key Management group to the HSM group. To do so, follow these steps:
Right-click on the HSM group that accepts the transaction, select Settings, and go to the Misc Settings tab.
From the Key Label Group drop-down menu, choose the correct Key Management Group. (such as, KMES-1).
Deselect Lookup Key Labels on the Guardian.
Select [ Update Group Settings ].
Select [ Finish ].