You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/payment-hsm/known-issues.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -34,7 +34,7 @@ After a reboot, either manual or as a result of a firmware upgrade, some Hosted
34
34
35
35
These errors occur under several circumstances: when accessing the payShield manager landing page, during sign-in or sign-out of payShield manager, and when using the JK host command. In the case of the JK host command, the error repeats after each attempt until a workaround is applied.
36
36
37
-
This issue is limited in scope. The problem only affects HSMs in a HOSTED HSM environment, and specifically those HSMs use SNMP or the JK host command. Hosted HSMs with SNMP disabled or those not utilizing the JK command don't experience these errors or related problems.
37
+
This issue is limited in scope. The problem only affects HSMs in a HOSTED HSM environment, and specifically those HSMs that use SNMP or the JK host command. Hosted HSMs with SNMP disabled or those not utilizing the JK command don't experience these errors or related problems.
38
38
39
39
The impact of this problem is minimal. While it does cause entries to appear in the payShield error log, it doesn't affect the operation of the payShield 10k in any way. Essentially, the issue is confined to log entries and doesn't compromise the functionality or performance of the system.
This article outlines the Azure Payment HSM prerequisites, support channels, and division of support responsibility between Microsoft, Thales, and the customer.
17
17
18
18
> [!NOTE]
19
-
> If a customer's production environment does not has a High Availability setup as shown in [Deployment scenarios: high availability deployment](deployment-scenarios.md#high-availability-deployment), customer will not receive S2 level support.
19
+
> If a customer's production environment doesn't have a high availability setup as shown in [Deployment scenarios: high availability deployment](deployment-scenarios.md#high-availability-deployment), the customer doesn't receive S2 level support.
20
20
21
21
## Prerequisites
22
22
23
23
Microsoft works with Thales to ensure that customers meet the prerequisites before starting the onboarding process.
24
24
25
25
- Customers must have access to the [Thales CPL Customer Support Portal](https://supportportal.thalesgroup.com/csm) (Customer ID).
26
-
- Customers must have Thales smart cards and card readers for payShield Manager. If a customer need to purchase smart cards or card readers they should contact their Thales representatives, or find their contacts through the [Thales contact page](https://cpl.thalesgroup.com/contact-us):
26
+
- Customers must have Thales smart cards and card readers for payShield Manager. If a customer needs to purchase smart cards or card readers, they should contact their Thales representatives or find their contacts through the [Thales contact page](https://cpl.thalesgroup.com/contact-us):
27
27
-**Item**: 971-000135-001-000
28
28
-**Description**: PS10-RMGT-KIT2 - payShield Manager Starter Kit - for software V1.4A (1.8.3) and higher
The only smart cards compatible with the ciphers used to enable over-network use smart cards have a blue band and are labeled "payShield Manager Card".
32
-
- If a customer need to purchase a payShield Trusted Management Device (TMD), they should contact their Thales representatives or find their contacts through the [Thales contact page](https://cpl.thalesgroup.com/contact-us).
32
+
- If a customer needs to purchase a payShield Trusted Management Device (TMD), they should contact their Thales representatives or find their contacts through the [Thales contact page](https://cpl.thalesgroup.com/contact-us).
33
33
- Customers must download and review the "Hosted HSM End User Guide," which is available through the Thales CPL Customer Support Portal. The Hosted HSM End User Guide provides more details on the changes to payShield to this service.
34
-
- Customers must review the "Azure Payment HSM - Get Ready for payShield 10K" guide that they received from Microsoft. (Customers who do not have the guide may request it from [Microsoft Support](#microsoft-support).)
34
+
- Customers must review the "Azure Payment HSM - Get Ready for payShield 10K" guide that they received from Microsoft. (Customers who don't have the guide may request it from [Microsoft Support](#microsoft-support).)
35
35
- If a customer is new to payShield or the remote management option, they should take the formal training courses available from Thales and its approved partners.
36
36
- If a customer is using payShield on premises today with custom firmware, they must conduct a porting exercise to update the firmware to a version compatible with the Azure deployment. To request a quote, contact a Thales account manager.
Copy file name to clipboardExpand all lines: articles/payment-hsm/whats-new.md
+5-5Lines changed: 5 additions & 5 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -14,17 +14,17 @@ Here's what's new with Azure Payment HSM.
14
14
15
15
## December 2025
16
16
17
-
Azure Payment HSM upgraded the base firmware to 2.2b. Please refer Thales release notes for new features and bug fixes.
17
+
Azure Payment HSM upgraded the base firmware to 2.2b. Please refer to the Thales release notes for new features and bug fixes.
18
18
19
19
## September 2024
20
20
21
-
Azure Payment HSM upgraded the base firmware to 1.9a. Refer the [Thales payShield 10K](https://cpl.thalesgroup.com/encryption/hardware-security-modules/payment-hsms/payshield-10k) release notes for new features and bug fixes in the firmware1.8a release.
21
+
Azure Payment HSM upgraded the base firmware to 1.9a. For new features and bug fixes in the firmware 1.8a release, see the [Thales payShield 10K](https://cpl.thalesgroup.com/encryption/hardware-security-modules/payment-hsms/payshield-10k) release notes.
22
22
23
23
## May 2023
24
24
25
25
Azure Payment HSM now supports two host IP network interfaces from payShield 10K. Customers using two host network interfaces can now have a maximum of 128 concurrent connections.
26
26
27
-
It's important to note that there are no changes to the payment HSM resource creation process, as the two host network interfaces are created by default when the PHSM is set up. Additionally, customers can only create these host network interfaces within the same virtual network, but they can use either static or dynamic IP addresses for the host interfaces.
27
+
There are no changes to the payment HSM resource creation process, as the two host network interfaces are created by default when you set up the PHSM. Additionally, you can only create these host network interfaces within the same virtual network, but you can use either static or dynamic IP addresses for the host interfaces.
28
28
29
29
For more information, see:
30
30
-[Create a payment HSM with the host and management port in the same virtual network using Azure CLI or PowerShell](create-payment-hsm.md)
@@ -35,9 +35,9 @@ For more information, see:
35
35
36
36
## April 2023
37
37
38
-
Azure Payment HSM traffic inspection with UDR and NSG not supported.
38
+
Azure Payment HSM doesn't support traffic inspection by using UDR and NSG.
39
39
40
-
Currently, payment HSM isn't compatible with vWAN topologies or cross region virtual network peering, as listed in the [topology supported](solution-design.md#supported-topologies). Payment HSM comes with some [policy restrictions](solution-design.md#constraints) on these subnets: **Network Security Groups (NSGs) and User-Defined Routes (UDRs) are currently not supported**. It's possible to bypass the current UDR restriction and inspect traffic destined to a Payment HSM. [This article](inspect-traffic.md) presents two ways: a [firewall with source network address translation (SNAT)](inspect-traffic.md#firewall-with-source-network-address-translation-snat) and a [firewall with reverse proxy](inspect-traffic.md#firewall-with-reverse-proxy).
40
+
Currently, Payment HSM isn't compatible with vWAN topologies or cross region virtual network peering, as listed in the [topology supported](solution-design.md#supported-topologies). Payment HSM comes with some [policy restrictions](solution-design.md#constraints) on these subnets: **Network Security Groups (NSGs) and User-Defined Routes (UDRs) are currently not supported**. You can bypass the current UDR restriction and inspect traffic destined to a Payment HSM. [This article](inspect-traffic.md) presents two ways: a [firewall with source network address translation (SNAT)](inspect-traffic.md#firewall-with-source-network-address-translation-snat) and a [firewall with reverse proxy](inspect-traffic.md#firewall-with-reverse-proxy).
0 commit comments