Skip to content

Commit 68891c2

Browse files
authored
Merge pull request #103411 from barclayn/dedicated-hsm-updates
update dedicated hsm regions per John Dawson
2 parents c407309 + 4cd07c5 commit 68891c2

File tree

2 files changed

+19
-12
lines changed

2 files changed

+19
-12
lines changed

articles/dedicated-hsm/deployment-architecture.md

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@ ms.workload: identity
1010
ms.tgt_pltfrm: na
1111
ms.devlang: na
1212
ms.topic: conceptual
13-
ms.date: 11/11/2019
13+
ms.date: 02/05/2020
1414
ms.author: mbaldwin
1515

1616
---
@@ -28,10 +28,13 @@ The HSMs are distributed across Microsoft’s data centers and can be easily pro
2828
* East US
2929
* East US 2
3030
* West US
31-
* West US 2
3231
* South Central US
3332
* Southeast Asia
3433
* East Asia
34+
* India Central
35+
* India South
36+
* Japan East
37+
* Japan West
3538
* North Europe
3639
* West Europe
3740
* UK South

articles/dedicated-hsm/faq.md

Lines changed: 14 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ ms.tgt_pltfrm: na
1212
ms.devlang: na
1313
ms.topic: conceptual
1414
ms.custom: mvc
15-
ms.date: 5/8/2019
15+
ms.date: 02/05/2020
1616
ms.author: mbaldwin
1717
#Customer intent: As an IT Pro, Decision maker I am looking for key storage capability within Azure Cloud that meets FIPS 140-2 Level 3 certification and that gives me exclusive access to the hardware.
1818

@@ -45,7 +45,7 @@ Customers can provision HSMs in specific regions using PowerShell or command-lin
4545

4646
### Q: What software is provided with the Dedicated HSM service?
4747

48-
Gemalto supplies all software for the HSM device once provisioned by Microsoft. The software is available at the [Gemalto customer support portal](https://supportportal.gemalto.com/csm/). Customers using the Dedicated HSM service are required to be registered for Gemalto support and have a Customer ID that enables access and download of relevant software. The supported client software is version 7.2 which is compatible with the FIPS 140-2 Level 3 validated firmware version 7.0.3.
48+
Gemalto supplies all software for the HSM device once provisioned by Microsoft. The software is available at the [Gemalto customer support portal](https://supportportal.gemalto.com/csm/). Customers using the Dedicated HSM service are required to be registered for Gemalto support and have a Customer ID that enables access and download of relevant software. The supported client software is version 7.2, which is compatible with the FIPS 140-2 Level 3 validated firmware version 7.0.3.
4949

5050
### Q: Does Azure Dedicated HSM offer Password-based and PED-based authentication?
5151

@@ -57,7 +57,7 @@ Microsoft only offers the Gemalto SafeNet Luna Network HSM via the Dedicated HSM
5757

5858
### Q: Does Azure Dedicated HSM support payment (PIN/EFT) features?
5959

60-
The Azure Dedicated HSM service uses SafeNet Luna Network HSM 7 (model A790) devices. These devices do not support payment HSM specific functionality (such as PIN or EFT) or certifications. If you would like Azure Dedicated HSM service to support payment HSMs in future, please pass on the feedback to your Microsoft Account Representative.
60+
The Azure Dedicated HSM service uses SafeNet Luna Network HSM 7 (model A790) devices. These devices do not support payment HSM specific functionality (such as PIN or EFT) or certifications. If you would like Azure Dedicated HSM service to support payment HSMs in future, pass on the feedback to your Microsoft Account Representative.
6161

6262
### Q: Which Azure regions is Dedicated HSM available in?
6363

@@ -69,6 +69,10 @@ As of late March 2019, Dedicated HSM is available in the 14 regions listed below
6969
* South Central US
7070
* Southeast Asia
7171
* East Asia
72+
* India Central
73+
* India South
74+
* Japan East
75+
* Japan West
7276
* North Europe
7377
* West Europe
7478
* UK South
@@ -119,7 +123,7 @@ PKCS#11, Java (JCA/JCE), Microsoft CAPI, and CNG, OpenSSL
119123

120124
### Q: Can I import/migrate keys from Luna 5/6 HSMs to Azure Dedicated HSMs?
121125

122-
Yes. Please refer to the Gemalto migration guide.
126+
Yes. Refer to the Gemalto migration guide.
123127

124128
## Using your HSM
125129

@@ -150,19 +154,19 @@ Yes. Each HSM appliance is fully dedicated to one single customer and no one els
150154

151155
### Q: What level of access does Microsoft have to my HSM?
152156

153-
Microsoft does not have any administrative or cryptographic control over the HSM. Microsoft does have monitor level access via serial port connection to retrieve basic telemetry such as temperature and component health. This allows Microsoft to provide proactive notification of health issues. If required, the customer can disable this account.
157+
Microsoft does not have any administrative or cryptographic control over the HSM. Microsoft does have monitor level access via serial port connection to retrieve basic telemetry such as temperature and component health. This allows Microsoft to provide proactive notification of health issues. If necessary, the customer can disable this account.
154158

155159
### Q: What is the "tenantadmin" account Microsoft uses, I am used to the admin user being "admin" on SafeNet HSMs?
156160

157-
The HSM device ships with a default user of admin with its usual default password. Microsoft did not want to have default passwords in use while any device is in a pool waiting to be provisioned by customers. This would not meet our strict security requirements. For this reason, we set a strong password which is discarded at provisioning time. Also, at provisioning time we create a new user in the admin role called "tenantadmin". This user has the default password and customers change this as the first action when first logging into the newly provisioned device. This process ensures high degrees of security and maintains our promise of sole administrative control for our customers. It should be noted that the "tenantadmin" user can be used to reset the admin user password if a customer prefers to use that account.
161+
The HSM device ships with a default user of admin with its usual default password. Microsoft did not want to have default passwords in use while any device is in a pool waiting to be provisioned by customers. This would not meet our strict security requirements. For this reason, we set a strong password, which is discarded at provisioning time. Also, at provisioning time we create a new user in the admin role called "tenantadmin". This user has the default password and customers change this as the first action when first logging into the newly provisioned device. This process ensures high degrees of security and maintains our promise of sole administrative control for our customers. It should be noted that the "tenantadmin" user can be used to reset the admin user password if a customer prefers to use that account.
158162

159163
### Q: Can Microsoft or anyone at Microsoft access keys in my Dedicated HSM?
160164

161165
No. Microsoft does not have any access to the keys stored in customer allocated Dedicated HSM.
162166

163167
### Q: Can I upgrade software/firmware on HSMs allocated to me?
164168

165-
To get best support, Microsoft strongly recommends not to upgrade software/firmware on the HSM. However, the customer does have full administrative control including upgrading software/firmware if specific features are required from different firmware versions. Before making changes, the implications must be understood as this could, for example, effect FIPS validated status.
169+
To get best support, Microsoft strongly recommends not to upgrade software/firmware on the HSM. However, the customer does have full administrative control including upgrading software/firmware if specific features are required from different firmware versions. Before making changes, the implications must be understood as this could, for example, affect FIPS validated status.
166170

167171
### Q: How do I manage Dedicated HSM?
168172

@@ -196,7 +200,7 @@ No.
196200

197201
### Q: How many HSMs can I add to the same high availability configuration from one single application?
198202

199-
16 members of an HA group has under-gone, full-throttle testing with excellent results.
203+
16 members of an HA group have under-gone, full-throttle testing with excellent results.
200204

201205
## Support
202206

@@ -218,7 +222,7 @@ It is highly recommended to use an on-premises HSM backup device to perform regu
218222

219223
### Q: How do I get support for Dedicated HSM?
220224

221-
Support is provided by both Microsoft and Gemalto. If you have an issue with the hardware or network access, raise a support request with Microsoft and if you have an issue with HSM configuration, software and application development please raise a support request with Gemalto. If you have an undetermined issue, raise a support request with Microsoft and then Gemalto can be engaged as required.
225+
Support is provided by both Microsoft and Gemalto. If you have an issue with the hardware or network access, raise a support request with Microsoft and if you have an issue with HSM configuration, software, and application development raise a support request with Gemalto. If you have an undetermined issue, raise a support request with Microsoft and then Gemalto can be engaged as required.
222226

223227
### Q: How do I get the client software, documentation and access to integration guidance for the SafeNet Luna 7 HSM?
224228

@@ -230,7 +234,7 @@ Microsoft does not have the ability to connect to HSMs allocated to customers. C
230234

231235
### Q: What if I need to reboot my HSM?
232236

233-
The HSM has a command line reboot option, however, we are experiencing reboot hang issues intermittently and for this reason it is recommended for the safest reboot that you raise a support request with Microsoft to have the device physically rebooted.
237+
The HSM has a command-line reboot option, however, we are experiencing reboot hang issues intermittently and for this reason it is recommended for the safest reboot that you raise a support request with Microsoft to have the device physically rebooted.
234238

235239
## Cryptography and standards
236240

0 commit comments

Comments
 (0)