Skip to content

Commit 17b55ab

Browse files
Merge pull request #216579 from msmbaldwin/patch-168
Update deployment-scenarios.md
2 parents 7cb8015 + 18e022b commit 17b55ab

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

articles/payment-hsm/deployment-scenarios.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ Microsoft deploys payment hardware security modules (HSM) in stamps within a reg
2020
Thales doesn't provide PayShield SDK to customers, which supports HA over a cluster (a collection of HSMs initialized with same LMK). However, the customers usage scenario of the Thales PayShield devices is like a Stateless Server. Thus, no synchronization is required between HSMs during application runtime. Customers handle the HA using their custom client. One implementation would be to load balance between healthy HSMs connected to the application. Customers are responsible for implementing high availability by provisioning multiple devices, load balancing them, and using any kind of available backup mechanism to back up keys.
2121

2222
> [!IMPORTANT]
23-
> - Virtual network peering does support cross-region communication between payment HSM instances. A payment HSM instance in one region cannot communicate with a payment HSM instance in another region.
23+
> - Virtual network peering does not support cross-region communication between payment HSM instances. A payment HSM instance in one region cannot communicate with a payment HSM instance in another region.
2424
> - NSGs are not supported for payment HSM subnet.
2525
> - Customers can allocate a maximum of two payment HSMs from each stamp in one region under same subscription.
2626
> - If customer does not have a High Availability setup in their production environment, the customer will not be able to receive S2 support from Microsoft side.

0 commit comments

Comments
 (0)