You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/dedicated-hsm/faq.md
+14-10Lines changed: 14 additions & 10 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -12,7 +12,7 @@ ms.tgt_pltfrm: na
12
12
ms.devlang: na
13
13
ms.topic: conceptual
14
14
ms.custom: mvc
15
-
ms.date: 5/8/2019
15
+
ms.date: 02/05/2020
16
16
ms.author: mbaldwin
17
17
#Customer intent: As an IT Pro, Decision maker I am looking for key storage capability within Azure Cloud that meets FIPS 140-2 Level 3 certification and that gives me exclusive access to the hardware.
18
18
@@ -45,7 +45,7 @@ Customers can provision HSMs in specific regions using PowerShell or command-lin
45
45
46
46
### Q: What software is provided with the Dedicated HSM service?
47
47
48
-
Gemalto supplies all software for the HSM device once provisioned by Microsoft. The software is available at the [Gemalto customer support portal](https://supportportal.gemalto.com/csm/). Customers using the Dedicated HSM service are required to be registered for Gemalto support and have a Customer ID that enables access and download of relevant software. The supported client software is version 7.2 which is compatible with the FIPS 140-2 Level 3 validated firmware version 7.0.3.
48
+
Gemalto supplies all software for the HSM device once provisioned by Microsoft. The software is available at the [Gemalto customer support portal](https://supportportal.gemalto.com/csm/). Customers using the Dedicated HSM service are required to be registered for Gemalto support and have a Customer ID that enables access and download of relevant software. The supported client software is version 7.2, which is compatible with the FIPS 140-2 Level 3 validated firmware version 7.0.3.
49
49
50
50
### Q: Does Azure Dedicated HSM offer Password-based and PED-based authentication?
51
51
@@ -57,7 +57,7 @@ Microsoft only offers the Gemalto SafeNet Luna Network HSM via the Dedicated HSM
57
57
58
58
### Q: Does Azure Dedicated HSM support payment (PIN/EFT) features?
59
59
60
-
The Azure Dedicated HSM service uses SafeNet Luna Network HSM 7 (model A790) devices. These devices do not support payment HSM specific functionality (such as PIN or EFT) or certifications. If you would like Azure Dedicated HSM service to support payment HSMs in future, please pass on the feedback to your Microsoft Account Representative.
60
+
The Azure Dedicated HSM service uses SafeNet Luna Network HSM 7 (model A790) devices. These devices do not support payment HSM specific functionality (such as PIN or EFT) or certifications. If you would like Azure Dedicated HSM service to support payment HSMs in future, pass on the feedback to your Microsoft Account Representative.
61
61
62
62
### Q: Which Azure regions is Dedicated HSM available in?
63
63
@@ -69,6 +69,10 @@ As of late March 2019, Dedicated HSM is available in the 14 regions listed below
69
69
* South Central US
70
70
* Southeast Asia
71
71
* East Asia
72
+
* India Central
73
+
* India South
74
+
* Japan East
75
+
* Japan West
72
76
* North Europe
73
77
* West Europe
74
78
* UK South
@@ -119,7 +123,7 @@ PKCS#11, Java (JCA/JCE), Microsoft CAPI, and CNG, OpenSSL
119
123
120
124
### Q: Can I import/migrate keys from Luna 5/6 HSMs to Azure Dedicated HSMs?
121
125
122
-
Yes. Please refer to the Gemalto migration guide.
126
+
Yes. Refer to the Gemalto migration guide.
123
127
124
128
## Using your HSM
125
129
@@ -150,19 +154,19 @@ Yes. Each HSM appliance is fully dedicated to one single customer and no one els
150
154
151
155
### Q: What level of access does Microsoft have to my HSM?
152
156
153
-
Microsoft does not have any administrative or cryptographic control over the HSM. Microsoft does have monitor level access via serial port connection to retrieve basic telemetry such as temperature and component health. This allows Microsoft to provide proactive notification of health issues. If required, the customer can disable this account.
157
+
Microsoft does not have any administrative or cryptographic control over the HSM. Microsoft does have monitor level access via serial port connection to retrieve basic telemetry such as temperature and component health. This allows Microsoft to provide proactive notification of health issues. If necessary, the customer can disable this account.
154
158
155
159
### Q: What is the "tenantadmin" account Microsoft uses, I am used to the admin user being "admin" on SafeNet HSMs?
156
160
157
-
The HSM device ships with a default user of admin with its usual default password. Microsoft did not want to have default passwords in use while any device is in a pool waiting to be provisioned by customers. This would not meet our strict security requirements. For this reason, we set a strong password which is discarded at provisioning time. Also, at provisioning time we create a new user in the admin role called "tenantadmin". This user has the default password and customers change this as the first action when first logging into the newly provisioned device. This process ensures high degrees of security and maintains our promise of sole administrative control for our customers. It should be noted that the "tenantadmin" user can be used to reset the admin user password if a customer prefers to use that account.
161
+
The HSM device ships with a default user of admin with its usual default password. Microsoft did not want to have default passwords in use while any device is in a pool waiting to be provisioned by customers. This would not meet our strict security requirements. For this reason, we set a strong password, which is discarded at provisioning time. Also, at provisioning time we create a new user in the admin role called "tenantadmin". This user has the default password and customers change this as the first action when first logging into the newly provisioned device. This process ensures high degrees of security and maintains our promise of sole administrative control for our customers. It should be noted that the "tenantadmin" user can be used to reset the admin user password if a customer prefers to use that account.
158
162
159
163
### Q: Can Microsoft or anyone at Microsoft access keys in my Dedicated HSM?
160
164
161
165
No. Microsoft does not have any access to the keys stored in customer allocated Dedicated HSM.
162
166
163
167
### Q: Can I upgrade software/firmware on HSMs allocated to me?
164
168
165
-
To get best support, Microsoft strongly recommends not to upgrade software/firmware on the HSM. However, the customer does have full administrative control including upgrading software/firmware if specific features are required from different firmware versions. Before making changes, the implications must be understood as this could, for example, effect FIPS validated status.
169
+
To get best support, Microsoft strongly recommends not to upgrade software/firmware on the HSM. However, the customer does have full administrative control including upgrading software/firmware if specific features are required from different firmware versions. Before making changes, the implications must be understood as this could, for example, affect FIPS validated status.
166
170
167
171
### Q: How do I manage Dedicated HSM?
168
172
@@ -196,7 +200,7 @@ No.
196
200
197
201
### Q: How many HSMs can I add to the same high availability configuration from one single application?
198
202
199
-
16 members of an HA group has under-gone, full-throttle testing with excellent results.
203
+
16 members of an HA group have under-gone, full-throttle testing with excellent results.
200
204
201
205
## Support
202
206
@@ -218,7 +222,7 @@ It is highly recommended to use an on-premises HSM backup device to perform regu
218
222
219
223
### Q: How do I get support for Dedicated HSM?
220
224
221
-
Support is provided by both Microsoft and Gemalto. If you have an issue with the hardware or network access, raise a support request with Microsoft and if you have an issue with HSM configuration, software and application development please raise a support request with Gemalto. If you have an undetermined issue, raise a support request with Microsoft and then Gemalto can be engaged as required.
225
+
Support is provided by both Microsoft and Gemalto. If you have an issue with the hardware or network access, raise a support request with Microsoft and if you have an issue with HSM configuration, software, and application development raise a support request with Gemalto. If you have an undetermined issue, raise a support request with Microsoft and then Gemalto can be engaged as required.
222
226
223
227
### Q: How do I get the client software, documentation and access to integration guidance for the SafeNet Luna 7 HSM?
224
228
@@ -230,7 +234,7 @@ Microsoft does not have the ability to connect to HSMs allocated to customers. C
230
234
231
235
### Q: What if I need to reboot my HSM?
232
236
233
-
The HSM has a commandline reboot option, however, we are experiencing reboot hang issues intermittently and for this reason it is recommended for the safest reboot that you raise a support request with Microsoft to have the device physically rebooted.
237
+
The HSM has a command-line reboot option, however, we are experiencing reboot hang issues intermittently and for this reason it is recommended for the safest reboot that you raise a support request with Microsoft to have the device physically rebooted.
0 commit comments