Edit

Authentication and access control for Azure Payment HSM v2

Azure Payment HSM v2 protects two distinct control planes: the HSM interfaces that process payment cryptography, and the Azure resource that represents the cluster. Clients authenticate to the HSM interfaces over mutual TLS, administrators authenticate to the HSM with smart cards through the Secure Configuration Assistant (SCA), and Azure role-based access control (RBAC) governs access to the Azure resource. This article explains each mechanism and links to the procedures that implement it.

Client authentication with mutual TLS

Azure Payment HSM v2 exposes a management interface and an application interface, and both require mutually authenticated TLS. Each interface trusts a certification authority (CA) certificate that you provide when you deploy the cluster, and clients present certificates issued from that CA to connect.

  • Use a self-signed root CA on the NIST P-256 curve. Each trusted issuer must be a self-signed root CA certificate whose key is an elliptic curve (EC) public key on the NIST P-256 (prime256v1) curve. Azure Payment HSM v2 doesn't support intermediate CA certificates or other cryptographic algorithms or key types. For more information, see Establish client trust.

  • Provide separate trust anchors for the management and application interfaces. Supply a distinct management-port trusted issuer and application-port trusted issuer when you create the cluster, so that administrative access and payment-application access rely on independent certificate chains. For more information, see Create a Payment HSM v2 instance.

  • Confirm that mutual TLS is active before you operate. The SCA shows a connection icon and a green lock icon when a mutually authenticated session is established. Verify these indicators before you administer the cluster. For more information, see Frequently asked questions about Azure Payment HSM v2.

HSM administrator credentials

Administrators manage the HSM with the Utimaco SCA and physical credentials. Possession of these credentials grants administrative and key-loading access, so protect them like any other high-value secret.

  • Administer the HSM with the SCA, smart cards, and the C3 Key Loading Device (KLD). Use the SCA with administrator and backup smart cards and the C3 KLD for HSM setup, user management, key management, and backup operations. For more information, see Connect to Azure Payment HSM v2.

  • Store smart cards and the KLD according to your credential-management policy. The administrator and backup smart cards and the C3 KLD authenticate administration and key loading, so restrict physical custody and store them securely. For more information, see Perform Azure Payment HSM v2 operations.

  • Apply least privilege through security associations and use policies. Initialize the HSM with a security association and define use policies so that administrators and applications receive only the permissions their tasks require. For more information, see Perform Azure Payment HSM v2 operations.

Azure access control

Access to the Azure resource that represents the cluster is separate from HSM administration. Use Azure RBAC to control who can create and manage the cluster and its dependent networking resources.

  • Grant least-privilege permissions to manage the cluster. Give only trusted identities the Azure permissions needed to create and manage the paymentHsmClusters resource, private endpoints, private DNS zones, and the subscription feature registration that the service requires. For more information, see Prepare your environment.