AWS đám mây HSM AWS cloud HSM AWS Cloud HSM
Hướng dẫn chi tiết đồng bộ từ docs Cloudflare — mỗi section có backlink tới đúng vị trí trên trang gốc. Detailed guide synced from Cloudflare docs — each section links to the matching anchor on the official page. មគ្គុទ្ទេសក៍លម្អិតធ្វើសមកាលពី docs Cloudflare — ផ្នែកនីមួយៗមានតំណទៅទីតាំងត្រូវគ្នានៅទំព័រផ្លូវការ។
← Danh mục ← Catalog ← បញ្ជីGiải thích nhanh Quick context បរិបទរហ័ស
Thuộc nhóm Application Services — tập trung bảo vệ, tăng tốc và vận hành ứng dụng/web phía trước origin. Tutorial «AWS cloud HSM» giúp bạn làm quen luồng triển khai thật — phù hợp đọc trước khi mở tài liệu gốc tiếng Anh. Docs gốc chia khoảng 2 bước chính; bản tóm tắt dưới đây giúp bạn nắm khung trước khi làm theo từng lệnh.
Learn how to use Keyless SSL with AWS CloudHSM.
ស្វែងយល់ពីរបៀបប្រើ Keyless SSL ជាមួយ AWS CloudHSM ។
Lưu ý Note ចំណាំ
Lưu ý trước khi làm Notes before you start ចំណាំមុនពេលចាប់ផ្តើម
- Đây là bản tóm tắt trên Orange Cloud Learning Hub — không thay thế tài liệu chính thức.
- Luôn mở liên kết «Tài liệu gốc» bên dưới khi cần lệnh CLI, snippet code và ảnh minh họa đầy đủ.
- Yêu cầu trước (từ docs): Provisioned an AWS CloudHSM cluster ↗ . · Cài đặted the appropriate software library for PKCS#11 ↗.
- Docs Cloudflare cập nhật thường xuyên — đối chiếu ngày «Rà soát lần cuối» trên trang gốc khi triển khai production.
- This is a summary on Orange Cloud Learning Hub — it does not replace the official documentation.
- Open the Official docs link below for CLI commands, code snippets, and full screenshots.
- Prerequisites (from docs): Provisioned an AWS CloudHSM cluster ↗ . · Installed the appropriate software library for PKCS#11 ↗.
- Cloudflare docs change frequently — verify the Last reviewed date on the official page before production use.
- នេះគឺជាការសង្ខេបនៅលើ Orange Cloud Learning Hub — វាមិនជំនួសឯកសារផ្លូវការទេ។
- បើកតំណឯកសារផ្លូវការខាងក្រោមសម្រាប់ពាក្យបញ្ជា CLI កូដ snippets និងរូបថតអេក្រង់ពេញ។
- តម្រូវការជាមុន (ពីឯកសារ)៖ ផ្តល់ជូនក្រុម AWS CloudHSM ↗ ។ · បានដំឡើងបណ្ណាល័យកម្មវិធីដែលសមរម្យសម្រាប់ PKCS#11 ↗។
- Cloudflare ឯកសារផ្លាស់ប្តូរជាញឹកញាប់ — ផ្ទៀងផ្ទាត់កាលបរិច្ឆេទដែលបានពិនិត្យចុងក្រោយនៅលើទំព័រផ្លូវការមុនពេលប្រើប្រាស់ផលិតកម្ម។
Overview Overview ទិដ្ឋភាពទូទៅ
Phần «Tổng quan» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.
Read the "Overview" section below — open the official docs link for full screenshots and configuration tabs.
អានផ្នែក «ទិដ្ឋភាពទូទៅ» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។
Trước khi bạn bắt đầu Before you start មុនពេលអ្នកចាប់ផ្តើម
Phần «Trước khi bắt đầu» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.
Read the "Before you start" section below — open the official docs link for full screenshots and configuration tabs.
អានផ្នែក «មុនពេលអ្នកចាប់ផ្តើម» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។
- Cung cấp một AWS CloudHSM cluster ↗ .
- Cài đặt appropriate software library for PKCS#11 ↗
- Provisioned an AWS CloudHSM cluster ↗ .
- Installed the appropriate software library for PKCS#11 ↗.
- បានផ្តល់ AWS CloudHSM cluster ↗ ។
- បានដំឡើង បណ្ណាល័យកម្មវិធីដែលសមរម្យសម្រាប់ PKCS#11 ↗។
1.Điều Nhập khóa công khai và riêng tư vào HSM 1. Import the public and private key to the HSM 1. នាំចូលសោសាធារណៈ និងឯកជនទៅកាន់ HSM
Phần «Import public và private key to HSM» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.
Read the "1. Import the public and private key to the HSM" section below — open the official docs link for full screenshots and configuration tabs.
អានផ្នែក «1. នាំចូលសោសាធារណៈ និងឯកជនទៅកាន់ HSM» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។
privkey.pem và sau đó chạy sau đây (thay thế certificate.pem bằng chứng chỉ thực tế của bạn) để điền pubkey.pm.privkey.pem and then run the following (replacing certificate.pem with your actual certificate) to populate pubkey.pm.privkey.pem ហើយបន្ទាប់មកដំណើរការដូចខាងក្រោម (ជំនួស certificate.pem ជាមួយវិញ្ញាបនបត្រពិតប្រាកដរបស់អ្នក) ដើម្បីបញ្ចូល pubkey.pm។keyserver$ openssl x509 -pubkey -noout -in certificate.pem > pubkey.pem keyserver$ /opt/cloudhsm/bin/key_mgmt_util
Command: loginHSM -u CU -s patrick -p donahue
Command: genSymKey -t 31 -s 16 -sess -l import-wrapping-key
...
Symmetric Key Created. Key Handle: 658
... Command: importPrivateKey -f privkey.pem -l mykey -id 1 -w 658
...
Cfm3WrapHostKey returned: 0x00 : HSM Return: SUCCESS
Cfm3CreateUnwrapTemplate returned: 0x00 : HSM Return: SUCCESS
Cfm3UnWrapKey returned: 0x00 : HSM Return: SUCCESS
...
Private Key Unwrapped. Key Handle: 658
Command: importPubKey -f pubkey.pem -l mykey -id 1
Cfm3CreatePublicKey returned: 0x00 : HSM Return: SUCCESS
...
Public Key Handle: 941
Command: logoutHSM
Command: exit 2.Đối với Thay đổi tệp cấu hình không gokeyless và khởi động lại dịch vụ 2. Modify the gokeyless config file and restart the service 2. កែប្រែឯកសារ gokeyless config ហើយចាប់ផ្តើមសេវាកម្មឡើងវិញ
Phần «Modify gokeyless config file và restart service» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.
Read the "2. Modify the gokeyless config file and restart the service" section below — open the official docs link for full screenshots and configuration tabs.
អានផ្នែក «2. កែប្រែឯកសារ gokeyless config ហើយចាប់ផ្តើមសេវាកម្មឡើងវិញ» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។
object=mykey và pin-value=username:password để khớp với khóa label bạn đã cung cấp và người dùng CU bạn đã tạo.object=mykey and pin-value=username:password values to match the key label you provided and CU user you created.object=mykey និង pin-value=username:password ដើម្បីផ្គូផ្គងស្លាកគន្លឹះដែលអ្នកបានផ្តល់ និងអ្នកប្រើប្រាស់ CU ដែលអ្នកបានបង្កើត។/etc/keyless/gokeyless.yaml và ngay sau đó:/etc/keyless/gokeyless.yaml and immediately after:/etc/keyless/gokeyless.yaml ហើយភ្លាមៗបន្ទាប់ពី៖private_key_stores:
- dir: /etc/keyless/keys - uri: pkcs11:token=cavium;object=mykey?module-path=/opt/cloudhsm/lib/libcloudhsm_pkcs11_standard.so&pin-value=patrick:donahue&max-sessions=1 gokeyless và xác minh nó đã bắt đầu thành công.gokeyless and verify it started successfully.gokeyless ហើយផ្ទៀងផ្ទាត់វាបានចាប់ផ្តើមដោយជោគជ័យ។sudo systemctl restart gokeyless.service
sudo systemctl status gokeyless.service -l {"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"item":{"@id":"/directory/","name":"Directory"}},{"@type":"ListItem","position":2,"item":{"@id":"/ssl/","name":"SSL/TLS"}},{"@type":"ListItem","position":3,"item":{"@id":"/ssl/keyless-ssl/","name":"Keyless SSL"}},{"@type":"ListItem","position":4,"item":{"@id":"/ssl/keyless-ssl/hardware-security-modules/","name":"Hardware security modules"}},{"@type":"ListItem","position":5,"item":{"@id":"/ssl/keyless-ssl/hardware-security-modules/aws-cloud-hsm/","name":"AWS cloud HSM"}}]} Xem bản đầy đủ trên developers.cloudflare.com (ảnh, tab cấu hình). View the full guide on developers.cloudflare.com (images, config tabs). មើលមគ្គុទ្ទេសក៍ពេញលើ developers.cloudflare.com (រូបភាព, tab កំណត់)។
Tài liệu gốc ↗ Official docs ↗ ឯកសារផ្លូវការ ↗