Tutorial Tutorial Tutorial Application Services Application Services Application Services ~37 phút ~37 min ~37 នាទី Đồng bộ 2026-06-10 Synced 2026-06-10 ធ្វើសមកាល 2026-06-10

Azure Dedicated HSM (HSM chuyên dụng) Azure Dedicated HSM Azure Dedicated HSM

Hướng dẫn chi tiết đồng bộ từ docs Cloudflare — mỗi section có backlink tới đúng vị trí trên trang gốc. Detailed guide synced from Cloudflare docs — each section links to the matching anchor on the official page. មគ្គុទ្ទេសក៍លម្អិតធ្វើសមកាលពី docs Cloudflare — ផ្នែកនីមួយៗមានតំណទៅទីតាំងត្រូវគ្នានៅទំព័រផ្លូវការ។

← Danh mục ← Catalog ← បញ្ជី

Giải thích nhanh Quick context បរិបទរហ័ស

Thuộc nhóm Application Services — tập trung bảo vệ, tăng tốc và vận hành ứng dụng/web phía trước origin. Tutorial «Azure Dedicated HSM» giúp bạn làm quen luồng triển khai thật — phù hợp đọc trước khi mở tài liệu gốc tiếng Anh. Docs gốc chia khoảng 4 bước chính; bản tóm tắt dưới đây giúp bạn nắm khung trước khi làm theo từng lệnh.

Learn how to use Keyless SSL with Azure Dedicated HSM.

ស្វែងយល់ពីរបៀបប្រើ Keyless SSL ជាមួយ Azure Dedicated HSM ។

Lưu ý Note ចំណាំ

Lưu ý trước khi làm Notes before you start ចំណាំមុនពេលចាប់ផ្តើម

  • Đây là bản tóm tắt trên Orange Cloud Learning Hub — không thay thế tài liệu chính thức.
  • Luôn mở liên kết «Tài liệu gốc» bên dưới khi cần lệnh CLI, snippet code và ảnh minh họa đầy đủ.
  • Yêu cầu trước (từ docs): Followed Microsoft's tutorial ↗ for deploying HSMs into Một virtual network using PowerShell · Cài đặted the SafeNet client software ↗
  • Docs Cloudflare cập nhật thường xuyên — đối chiếu ngày «Rà soát lần cuối» trên trang gốc khi triển khai production.
  • This is a summary on Orange Cloud Learning Hub — it does not replace the official documentation.
  • Open the Official docs link below for CLI commands, code snippets, and full screenshots.
  • Prerequisites (from docs): Followed Microsoft's tutorial ↗ for deploying HSMs into a virtual network using PowerShell · Installed the SafeNet client software ↗
  • Cloudflare docs change frequently — verify the Last reviewed date on the official page before production use.
  • នេះគឺជាការសង្ខេបនៅលើ Orange Cloud Learning Hub — វាមិនជំនួសឯកសារផ្លូវការទេ។
  • បើកតំណឯកសារផ្លូវការខាងក្រោមសម្រាប់ពាក្យបញ្ជា CLI កូដ snippets និងរូបថតអេក្រង់ពេញ។
  • តម្រូវការជាមុន (ពីឯកសារ)៖ បានធ្វើតាមការណែនាំរបស់ Microsoft ↗ សម្រាប់ការដាក់ពង្រាយ HSMs ទៅក្នុងបណ្តាញនិម្មិតដោយប្រើ PowerShell · បានដំឡើងកម្មវិធី SafeNet client ↗
  • Cloudflare ឯកសារផ្លាស់ប្តូរជាញឹកញាប់ — ផ្ទៀងផ្ទាត់កាលបរិច្ឆេទដែលបានពិនិត្យចុងក្រោយនៅលើទំព័រផ្លូវការមុនពេលប្រើប្រាស់ផលិតកម្ម។

Overview Overview ទិដ្ឋភាពទូទៅ

Phần «Tổng quan» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Overview" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «ទិដ្ឋភាពទូទៅ» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Hướng dẫn này sử dụng Azure Dedicated HSM ↗ - một ứng dụng được chứng nhận FIPS 140-2 Level 3 dựa trên Gemalto SafeNet Luna a790.
This tutorial uses Azure Dedicated HSM ↗ — a FIPS 140-2 Level 3 certified implementation based on the Gemalto SafeNet Luna a790.
ការបង្រៀននេះប្រើ Azure Dedicated HSM ↗ — ការអនុវត្ត FIPt ផ្អែកលើកម្រិត 3 Gemalto SafeNet Luna a790.
---
---
---

Trước khi bạn bắt đầu Before you start មុនពេលអ្នកចាប់ផ្តើម

Phần «Trước khi bắt đầu» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Before you start" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «មុនពេលអ្នកចាប់ផ្តើម» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Hãy chắc chắn rằng bạn có:
Make sure you have:
ត្រូវប្រាកដថាអ្នកមាន៖
---
---
---

1.Điều Tạo, gán và khởi tạo một phân vùng mới 1. Create, assign, and initialize a new partition 1. បង្កើត កំណត់ និងចាប់ផ្តើមភាគថាសថ្មី។

Phần «Create, assign, và initialize mới partition» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "1. Create, assign, and initialize a new partition" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «1. បង្កើត កំណត់ និងចាប់ផ្តើមភាគថាសថ្មី។» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Bước đầu tiên là tạo một phân vùng HSM, có thể được coi là một HSM logic độc lập trong thiết bị Azure Dedicated HSM của bạn.
The first step is creating an HSM partition, which can be thought of as an independent logical HSM within your Azure Dedicated HSM device.
ជំហានដំបូងគឺការបង្កើតភាគថាស HSM ដែលអាចត្រូវបានគិតថាជា HSM ឡូជីខលឯករាជ្យនៅក្នុងឧបករណ៍ Azure Dedicated HSM របស់អ្នក។
text
vm$ ssh tenantadmin@hsm


[local_host] lunash:>hsm login

  Please enter the HSM Administrators' password:

  > ********


'hsm login' successful.


Command Result : 0 (Success)


[local_host] lunash:>partition create -partition KeylessSSL


          Type 'proceed' to create the partition, or

          'quit' to quit now.

          > proceed

'partition create' successful.


Command Result : 0 (Success)
Tiếp theo, phân vùng cần được gán cho máy khách, trong trường hợp này là máy chủ khóa của bạn.
Next, the partition needs to be assigned to the client, in this case your key server.
បន្ទាប់មក ភាគថាសត្រូវកំណត់ទៅ client ក្នុងករណីនេះម៉ាស៊ីនមេរបស់អ្នក។
Cửa sổ Terminal
Terminal window
បង្អួចស្ថានីយ
text
[local_host] lunash:>client assignpartition -client azure-keyless -partition KeylessSSL


'client assignPartition' successful.


Command Result : 0 (Success)
Sau khi phân vùng đã được gán, chạy lunacm từ máy chủ ảo của bạn và bắt đầu phân vùng.
After the partition has been assigned, run lunacm from your virtual server and initialize the partition.
បន្ទាប់​ពី​ភាគ​ថាស​ត្រូវ​បាន​កំណត់​រួច សូម​រត់ lunacm ពី​ម៉ាស៊ីន​បម្រើ​និម្មិត​របស់​អ្នក ហើយ​ចាប់ផ្តើម​ភាគថាស។
text
vm$ lunacm

lunacm (64-bit) v7.2.0-220. Copyright (c) 2018 SafeNet. All rights reserved.


  Available HSMs:


  Slot Id ->              0

  Label ->

  Serial Number ->        XXXXXXXXXXXXX

  Model ->                LunaSA 7.2.0

  Firmware Version ->     7.0.3

  Configuration ->        Luna User Partition With SO (PW) Signing With Cloning Mode

  Slot Description ->     Net Token Slot


  Current Slot Id: 0


lunacm:>partition init -label KeylessSSL -domain cloudflare


  Enter password for Partition SO: ********


  Re-enter password for Partition SO: ********


  You are about to initialize the partition.

  All contents of the partition will be destroyed.


  Are you sure you wish to continue?


  Type 'proceed' to continue, or 'quit' to quit now ->proceed


Command Result : No Error
---
---
---

2.Đối với Tạo một cặp khóa RSA và yêu cầu chữ ký chứng chỉ (CSR) 2. Generate a RSA key pair and certificate signing request (CSR) 2. បង្កើតគូសោ RSA និងសំណើចុះហត្ថលេខាលើវិញ្ញាបនបត្រ (CSR)

Phần «Tạo RSA key pair và certificate signing request (CSR)» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "2. Generate a RSA key pair and certificate signing request (CSR)" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «2. បង្កើតគូសោ RSA និងសំណើចុះហត្ថលេខាលើវិញ្ញាបនបត្រ (CSR)» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Trước khi chạy các lệnh dưới đây, hãy kiểm tra với nhóm bảo mật thông tin và/hoặc mã hóa của bạn để xác nhận các thủ tục tạo khóa được phê duyệt cho tổ chức của bạn.
Before running the commands below, check with your information security and/or cryptography team to confirm the approved key creation procedures for your organization.
មុនពេលដំណើរការពាក្យបញ្ជាខាងក្រោម សូមពិនិត្យជាមួយក្រុមសុវត្ថិភាពព័ត៌មាន និង/ឬគ្រីបគ្រីបរបស់អ្នក ដើម្បីបញ្ជាក់អំពីនីតិវិធីបង្កើតកូនសោដែលបានអនុម័តសម្រាប់ស្ថាប័នរបស់អ្នក។
text
# cmu generatekeypair -keyType=RSA -modulusBits=2048 -publicExponent=65537 -sign=1 -verify=1 -labelpublic=myrsakey -labelprivate=myrsakey -keygenmech=1


Please enter password for token in slot 0 : ********


# cmu list


Please enter password for token in slot 0 : ********

handle=51 label=myrsakey

handle=48 label=myrsakey
Sử dụng khóa được tạo trong bước trước, tạo ra một CSR có thể được gửi đến một Cơ quan Chứng chỉ (CA) đáng tin cậy công khai để ký.
Using the key created in the previous step, generate a CSR that can be sent to a publicly trusted Certificate Authority (CA) for signing.
ដោយប្រើសោដែលបានបង្កើតក្នុងជំហានមុន បង្កើត CSR ដែលអាចផ្ញើទៅកាន់អាជ្ញាធរវិញ្ញាបនបត្រដែលជឿទុកចិត្តជាសាធារណៈ (CA) សម្រាប់ការចុះហត្ថលេខា។
text
# cmu requestCertificate -c="US" -o="Example, Inc." -cn="azure-dedicatedhsm.example.com" -s="California" -l="San Francisco" -publichandle=48 -privatehandle=51 -outputfile="rsa.csr" -sha256withrsa


Please enter password for token in slot 0 : ********

Using "CKM_SHA256_RSA_PKCS" Mechanism
---
---
---

3 Cái Nhận và tải lên một chứng chỉ được ký từ Cơ quan Chứng chỉ của bạn (CA) 3. Obtain and upload a signed certificate from your Certificate Authority (CA) 3. ទទួលបាន និងបង្ហោះវិញ្ញាបនបត្រដែលបានចុះហត្ថលេខាពីអាជ្ញាធរវិញ្ញាបនបត្រ (CA) របស់អ្នក

Phần «Obtain và upload signed certificate từ your Certificate Authority (CA)» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "3. Obtain and upload a signed certificate from your Certificate Authority (CA)" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «3. ទទួលបាន និងបង្ហោះវិញ្ញាបនបត្រដែលបានចុះហត្ថលេខាពីអាជ្ញាធរវិញ្ញាបនបត្រ (CA) របស់អ្នក» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Cung cấp CSR được tạo trong bước trước cho CA ưa thích của tổ chức của bạn, chứng minh quyền kiểm soát miền của bạn theo yêu cầu, và sau đó tải xuống các chứng chỉ được ký SSL. Thực hiện theo các hướng dẫn được cung cấp trong Upload Keyless SSL Certificates.
Provide the CSR created in the previous step to your organization's preferred CA, demonstrate control of your domain as requested, and then download the signed SSL certificates. Follow the instructions provided in Upload Keyless SSL Certificates.
ផ្តល់ CSR ដែលបានបង្កើតក្នុងជំហានមុនទៅកាន់ CA ដែលពេញចិត្តរបស់ស្ថាប័នរបស់អ្នក បង្ហាញការគ្រប់គ្រងដែនរបស់អ្នកតាមការស្នើសុំ ហើយបន្ទាប់មកទាញយកវិញ្ញាបនបត្រ SSL ដែលបានចុះហត្ថលេខា។ អនុវត្តតាមការណែនាំដែលបានផ្ដល់ឱ្យនៅក្នុង ផ្ទុក​ឡើង​វិញ្ញាបនបត្រ Keyless SSL។
---
---
---

Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)

Bốn Thay đổi tập tin cấu hình không gokeyless của bạn và khởi động lại dịch vụ 4. Modify your gokeyless config file and restart the service 4. កែប្រែឯកសារកំណត់រចនាសម្ព័ន្ធ gokeyless របស់អ្នក ហើយចាប់ផ្តើមសេវាកម្មឡើងវិញ

Phần «Modify your gokeyless config file và restart service» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "4. Modify your gokeyless config file and restart the service" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «4. កែប្រែឯកសារកំណត់រចនាសម្ព័ន្ធ gokeyless របស់អ្នក ហើយចាប់ផ្តើមសេវាកម្មឡើងវិញ» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Cuối cùng, chúng ta cần sửa đổi tệp cấu hình mà máy chủ khóa sẽ đọc khi khởi động. Hãy chắc chắn thay đổi các giá trị object=mykey và pin-value=username:password để khớp với khóa label bạn cung cấp và người dùng CU bạn đã tạo.
Lastly, we need to modify the configuration file that the key server will read on startup. Be sure to change the object=mykey and pin-value=username:password values to match the key label you provided and CU user you created.
ចុងក្រោយ យើងត្រូវកែប្រែឯកសារកំណត់រចនាសម្ព័ន្ធដែលម៉ាស៊ីនមេសោនឹងអាននៅពេលចាប់ផ្ដើម។ ត្រូវប្រាកដថាផ្លាស់ប្តូរតម្លៃ object=mykey និង pin-value=username:password ដើម្បីផ្គូផ្គងស្លាកគន្លឹះដែលអ្នកបានផ្តល់ និងអ្នកប្រើប្រាស់ CU ដែលអ្នកបានបង្កើត។
Mở /etc/keyless/gokeyless.yaml và ngay sau đó:
Open /etc/keyless/gokeyless.yaml and immediately after:
បើក /etc/keyless/gokeyless.yaml ហើយភ្លាមៗបន្ទាប់ពី៖
YAML
YAML
YAML
text
private_key_stores:

  - dir: /etc/keyless/keys
Thêm vào:
add:
បន្ថែម៖
YAML
YAML
YAML
text
- uri: pkcs11:token=KeylessSSL;object=myrsakey?module-path=/usr/safenet/lunaclient/lib/libCryptoki2_64.so&pin-value=password&max-sessions=1
Với tập tin config được lưu, khởi động lại gokeyless và xác minh nó đã bắt đầu thành công.
With the config file saved, restart gokeyless and verify it started successfully.
ជាមួយនឹងឯកសារកំណត់រចនាសម្ព័ន្ធដែលបានរក្សាទុក សូមចាប់ផ្ដើម gokeyless ហើយផ្ទៀងផ្ទាត់វាបានចាប់ផ្តើមដោយជោគជ័យ។
Cửa sổ Terminal
Terminal window
បង្អួចស្ថានីយ
text
sudo systemctl restart gokeyless.service

sudo systemctl status gokeyless.service -l
json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"item":{"@id":"/directory/","name":"Directory"}},{"@type":"ListItem","position":2,"item":{"@id":"/ssl/","name":"SSL/TLS"}},{"@type":"ListItem","position":3,"item":{"@id":"/ssl/keyless-ssl/","name":"Keyless SSL"}},{"@type":"ListItem","position":4,"item":{"@id":"/ssl/keyless-ssl/hardware-security-modules/","name":"Hardware security modules"}},{"@type":"ListItem","position":5,"item":{"@id":"/ssl/keyless-ssl/hardware-security-modules/azure-dedicated-hsm/","name":"Azure Dedicated HSM"}}]}

Xem bản đầy đủ trên developers.cloudflare.com (ảnh, tab cấu hình). View the full guide on developers.cloudflare.com (images, config tabs). មើលមគ្គុទ្ទេសក៍ពេញលើ developers.cloudflare.com (រូបភាព, tab កំណត់)។

Tài liệu gốc ↗ Official docs ↗ ឯកសារផ្លូវការ ↗