Tutorial Tutorial Tutorial Application Services Application Services Application Services ~45 phút ~45 min ~45 នាទី Đồng bộ 2026-06-10 Synced 2026-06-10 ធ្វើសមកាល 2026-06-10

Azure quản lý HSM Azure Managed HSM Azure គ្រប់គ្រង HSM

Hướng dẫn chi tiết đồng bộ từ docs Cloudflare — mỗi section có backlink tới đúng vị trí trên trang gốc. Detailed guide synced from Cloudflare docs — each section links to the matching anchor on the official page. មគ្គុទ្ទេសក៍លម្អិតធ្វើសមកាលពី docs Cloudflare — ផ្នែកនីមួយៗមានតំណទៅទីតាំងត្រូវគ្នានៅទំព័រផ្លូវការ។

← Danh mục ← Catalog ← បញ្ជី

Giải thích nhanh Quick context បរិបទរហ័ស

Thuộc nhóm Application Services — tập trung bảo vệ, tăng tốc và vận hành ứng dụng/web phía trước origin. Tutorial «Azure Managed HSM» giúp bạn làm quen luồng triển khai thật — phù hợp đọc trước khi mở tài liệu gốc tiếng Anh. Docs gốc chia khoảng 5 bước chính; bản tóm tắt dưới đây giúp bạn nắm khung trước khi làm theo từng lệnh.

This tutorial uses Microsoft Azure's Managed HSM to deploy a VM with the Keyless SSL daemon. Follow these instructions to deploy your keyless server.

ការបង្រៀននេះប្រើ Microsoft Azure's Managed HSM ដើម្បីដាក់ពង្រាយ VM ជាមួយនឹងដេមិន Keyless SSL ។ អនុវត្តតាមការណែនាំទាំងនេះ ដើម្បីដាក់ឱ្យប្រើម៉ាស៊ីនមេដែលគ្មានសោរបស់អ្នក។

Lưu ý Note ចំណាំ

Lưu ý trước khi làm Notes before you start ចំណាំមុនពេលចាប់ផ្តើម

  • Đây là bản tóm tắt trên Orange Cloud Learning Hub — không thay thế tài liệu chính thức.
  • Luôn mở liên kết «Tài liệu gốc» bên dưới khi cần lệnh CLI, snippet code và ảnh minh họa đầy đủ.
  • Yêu cầu trước (từ docs): Followed Microsoft's tutorial ↗ for provisioning and activating the managed HSM · Set up a VM for your key server
  • Docs Cloudflare cập nhật thường xuyên — đối chiếu ngày «Rà soát lần cuối» trên trang gốc khi triển khai production.
  • This is a summary on Orange Cloud Learning Hub — it does not replace the official documentation.
  • Open the Official docs link below for CLI commands, code snippets, and full screenshots.
  • Prerequisites (from docs): Followed Microsoft's tutorial ↗ for provisioning and activating the managed HSM · Set up a VM for your key server
  • Cloudflare docs change frequently — verify the Last reviewed date on the official page before production use.
  • នេះគឺជាការសង្ខេបនៅលើ Orange Cloud Learning Hub — វាមិនជំនួសឯកសារផ្លូវការទេ។
  • បើកតំណឯកសារផ្លូវការខាងក្រោមសម្រាប់ពាក្យបញ្ជា CLI កូដ snippets និងរូបថតអេក្រង់ពេញ។
  • តម្រូវការជាមុន (ពីឯកសារ)៖ បានធ្វើតាមការបង្រៀនរបស់ Microsoft ↗ សម្រាប់ការផ្តល់ និងធ្វើឱ្យសកម្ម HSM ដែលបានគ្រប់គ្រង · ដំឡើង VM សម្រាប់ម៉ាស៊ីនមេរបស់អ្នក
  • Cloudflare ឯកសារផ្លាស់ប្តូរជាញឹកញាប់ — ផ្ទៀងផ្ទាត់កាលបរិច្ឆេទដែលបានពិនិត្យចុងក្រោយនៅលើទំព័រផ្លូវការមុនពេលប្រើប្រាស់ផលិតកម្ម។

Overview Overview ទិដ្ឋភាពទូទៅ

Phần «Tổng quan» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Overview" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «ទិដ្ឋភាពទូទៅ» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Hướng dẫn này sử dụng Microsoft Azure’s Managed HSM ↗ - một thực hiện được chứng nhận FIPS 140-2 Level 3 - để triển khai một VM với daemon SSL không khóa.
This tutorial uses Microsoft Azure’s Managed HSM ↗ — a FIPS 140-2 Level 3 certified implementation — to deploy a VM with the Keyless SSL daemon.
---
---
---
Hãy chắc chắn rằng bạn có:
Make sure you have:
ត្រូវប្រាកដថាអ្នកមាន៖
  • Tiếp theo là tutorial ↗ của Microsoft để cung cấp và kích hoạt HSM được quản lý
  • Thiết lập VM cho máy chủ chính của bạn
  • Followed Microsoft's tutorial ↗ for provisioning and activating the managed HSM
  • Set up a VM for your key server
  • បានធ្វើតាម ការបង្រៀន ↗ របស់ Microsoft សម្រាប់ការគ្រប់គ្រង SM
  • ដំឡើង VM សម្រាប់ម៉ាស៊ីនមេរបស់អ្នក។
---
---
---

1.Điều Tạo VM 1. Create a VM 1. បង្កើត VM

Tạo VM where you will deploy the keyless daemon.

Read the "1. Create a VM" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «1. បង្កើត VM» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Tạo một VM nơi bạn sẽ triển khai daemon không khóa.
Create a VM where you will deploy the keyless daemon.
បង្កើត VM ដែលអ្នកនឹងដាក់ពង្រាយដេមិនគ្មានសោ។
---
---
---

2.Đối với Cài đặt server keyless 2. Deploy the keyless server 2. ដាក់ពង្រាយម៉ាស៊ីនមេគ្មានសោ

Phần «Triển khai keyless server» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "2. Deploy the keyless server" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «2. ដាក់ពង្រាយម៉ាស៊ីនមេគ្មានសោ» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Theo these instructions để triển khai máy chủ không chìa khóa của bạn.
Follow these instructions to deploy your keyless server.
អនុវត្តតាម ការណែនាំទាំងនេះ ដើម្បីដាក់ពង្រាយម៉ាស៊ីនមេដែលគ្មានសោរបស់អ្នក។
---
---
---

Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)

3 Cái Cài đặt Azure CLI 3. Set up the Azure CLI 3. ដំឡើង Azure CLI

Phần «Thiết lập Azure CLI» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "3. Set up the Azure CLI" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «3. ដំឡើង Azure CLI» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Thiết lập Azure CLI (được sử dụng để access khóa riêng).
Set up the Azure CLI (used to access the private key).
ដំឡើង Azure CLI (ប្រើដើម្បី access សោឯកជន)។
Ví dụ, nếu bạn đang sử dụng macOS:
For example, if you were using macOS:
ឧទាហរណ៍ប្រសិនបើអ្នកកំពុងប្រើ macOS៖
Cửa sổ Terminal
Terminal window
បង្អួចស្ថានីយ
text
brew install azure-cli
---
---
---

Bốn Thiết lập Managed HSM 4. Set up the Managed HSM 4. ដំឡើង Managed HSM

Phần «Thiết lập Managed HSM» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "4. Set up the Managed HSM" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «4. ដំឡើង Managed HSM» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
  1. Đăng nhập thông qua Azure CLI và tạo một nhóm tài nguyên cho Managed HSM trong một trong các khu vực được hỗ trợ:
  1. Log in through the Azure CLI and create a resource group for the Managed HSM in one of the supported regions:
  1. ចូលតាមរយៈ Azure CLI ហើយបង្កើតក្រុមធនធានសម្រាប់ Managed HSM នៅក្នុងតំបន់ដែលគាំទ្រមួយ៖
Cửa sổ Terminal
Terminal window
បង្អួចស្ថានីយ
text
az login  
az group create --name HSMgroup --location southcentralus
Lưu ý: Để biết danh sách các khu vực được hỗ trợ, hãy xem Microsoft documentation ↗.
Note For a list of supported regions, see the Microsoft documentation ↗.
ចំណាំ សម្រាប់បញ្ជីនៃតំបន់ដែលគាំទ្រ សូមមើល ឯកសារ Microsoft ↗។
  1. Create, provision, and activate ↗ các HSM.
  2. Thêm khóa riêng của bạn vào keyvault, trả về URI bạn cần cho Step 4:
  1. Create, provision, and activate ↗ the HSM.
  2. Add your private key to the keyvault, which returns the URI you need for Step 4:
  1. បង្កើត ការផ្តល់ និងធ្វើឱ្យ HSM សកម្ម ↗
  2. បន្ថែមសោឯកជនរបស់អ្នកទៅ keyvault ដែលត្រឡប់ URI ដែលអ្នកត្រូវការសម្រាប់ Step 4៖
text
az keyvault key import --hsm-name "KeylessHSM" --name "hsm-pub-keyless" --pem-file server.key
  1. Nếu máy chủ khóa đang chạy trong một VM Azure trong cùng một tài khoản, hãy sử dụng Managed services để ủy quyền:
  1. If the key server is running in an Azure VM in the same account, use Managed services for authorization:
  1. ប្រសិនបើម៉ាស៊ីនមេសំខាន់កំពុងដំណើរការនៅក្នុង Azure VM នៅក្នុងគណនីតែមួយ សូមប្រើ Managed services សម្រាប់ការអនុញ្ញាត៖
1.Điều Cho phép các dịch vụ được quản lý trên VM trong UI. 2.Đối với Cung cấp cho người dùng dịch vụ của bạn (được liên kết với VM của bạn) quyền ký hiệu HSM " az keyvault role assignment create --hsm-name KeylessHSM --assignee $(az vm identity show --name "hsmtestvm" --resource-group "HSMgroup" --query principalId -o tsv) --scope / --role "Managed HSM Crypto User" "
1. Enable managed services on the VM in the UI. 2. Give your service user (associated with your VM) HSM sign permissions `` az keyvault role assignment create --hsm-name KeylessHSM --assignee $(az vm identity show --name "hsmtestvm" --resource-group "HSMgroup" --query principalId -o tsv) --scope / --role "Managed HSM Crypto User" ``
1. បើកដំណើរការសេវាកម្មដែលបានគ្រប់គ្រងនៅលើ VM នៅក្នុង UI ។ 2. ផ្តល់ឱ្យអ្នកប្រើប្រាស់សេវាកម្មរបស់អ្នក (associated ជាមួយ VM របស់អ្នក) ការអនុញ្ញាតចុះហត្ថលេខា HSM `` az keyvault role assignment create --hsm-name KeylessHSM --assignee $(az vm identity show --name "hsmtestvm" --resource-group "HSMgroup" --query principalId -o tsv) --scope / --role "Managed HSM Crypto User" ``
  1. Trong tệp gokeyless YAML, thêm URI từ Step 2 dưới private<em>key</em>stores. Xem README ↗ của chúng tôi cho một ví dụ.
  1. In the gokeyless YAML file, add the URI from Step 2 under private<em>key</em>stores. See our README ↗ for an example.
  1. នៅក្នុងឯកសារ gokeyless YAML បន្ថែម URI ពី Step 2 នៅក្រោម private<em>key</em>stores។ សូមមើល README ↗ របស់យើងជាឧទាហរណ៍។

5 Khởi động lại Gokeyless 5. Restart gokeyless 5. ចាប់ផ្ដើម gokeyless ឡើងវិញ

Phần «Restart gokeyless» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "5. Restart gokeyless" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «5. ចាប់ផ្ដើម gokeyless ឡើងវិញ» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Sau khi lưu tệp config, khởi động lại gokeyless và xác minh rằng nó đã bắt đầu thành công:
Once you save the config file, restart gokeyless and verify that it started successfully:
នៅពេលដែលអ្នករក្សាទុកឯកសារកំណត់រចនាសម្ព័ន្ធ សូមចាប់ផ្តើម gokeyless ហើយផ្ទៀងផ្ទាត់ថាវាបានចាប់ផ្តើមដោយជោគជ័យ៖
Cửa sổ Terminal
Terminal window
បង្អួចស្ថានីយ
text
sudo systemctl restart gokeyless.service

sudo systemctl status gokeyless.service -l
json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"item":{"@id":"/directory/","name":"Directory"}},{"@type":"ListItem","position":2,"item":{"@id":"/ssl/","name":"SSL/TLS"}},{"@type":"ListItem","position":3,"item":{"@id":"/ssl/keyless-ssl/","name":"Keyless SSL"}},{"@type":"ListItem","position":4,"item":{"@id":"/ssl/keyless-ssl/hardware-security-modules/","name":"Hardware security modules"}},{"@type":"ListItem","position":5,"item":{"@id":"/ssl/keyless-ssl/hardware-security-modules/azure-managed-hsm/","name":"Azure Managed HSM"}}]}

Xem bản đầy đủ trên developers.cloudflare.com (ảnh, tab cấu hình). View the full guide on developers.cloudflare.com (images, config tabs). មើលមគ្គុទ្ទេសក៍ពេញលើ developers.cloudflare.com (រូបភាព, tab កំណត់)។

Tài liệu gốc ↗ Official docs ↗ ឯកសារផ្លូវការ ↗