v1.1.0.03131
Azure Managed HSM offers a TLS Offload library which is compliant with PKCS#11 version 2.40. We do not support all possible functions listed in the PKCS#11 specification. Our TLS Offload library supports a limited set of functions and mechanisms for SSL/TLS Offload with F5 (BigIP) and Nginx only!
Supported Operating Systems
- RHEL 8.8 (mhsm-pkcs11-1.1.0.03131-1.el8.x86_64.rpm)
- SLES15.4 (mhsm-pkcs11-1.1.0.03131-1.x86_64.rpm)
- Ubuntu 20.04 and 22.04 (mhsm-pkcs11_1.1.0.03131_amd64.deb)
- Azure Linux 3.0 (mhsm-pkcs11-1.1.0.03131-1.azl3.x86_64.rpm)
Supported Key Types & Mechanisms
You can find a list of all supported key types and mechanisms here:
https://github.com/microsoft/AzureManagedHsmTLSOffload#supported-key-types--mechanisms
Not Supported
- AES Keys Not Supported.
- Encryption / Decryption Not Supported.
- Key Wrap Not Supported
- Triple Des (3DES) Not Supported
- Key Derivation Not Supported
- TLS Offload Library has also removed support for C_GenerateKey, C_GetOperationState, C_SetOperationState, C_EncryptInit, C_Encrypt, C_DecryptInit, C_Decrypt
Release Notes: What Changed
- Deprecated Mariner 2 as it reached end of life on July 31st, 2025.
- Added Azure Linux 3.0 package