Review HSM protection for Key Vault keys

Choose a key type that meets organizational protection requirements.

Description

Key Vault supports software-protected and HSM-protected keys. When HSM protection is required, the Premium tier supports RSA-HSM or EC-HSM to perform key operations within a hardware security boundary.

Potential impact

Software-protected keys may not meet an organizational or regulatory requirement for HSM protection.

Remediation

Confirm the need for HSM protection and choose a supported key type and algorithm. Changing key_type recreates the key resource, so plan continued decryption of existing data and consumer migration first.

Examples

The examples use RSA-HSM. The referenced Key Vault must use the Premium tier.

Before

hcl
resource "azurerm_key_vault_key" "example" {
  name         = "application-key"
  key_vault_id = azurerm_key_vault.example.id
  key_type     = "RSA"
  key_size     = 3072
  key_opts     = ["encrypt", "decrypt", "wrapKey", "unwrapKey"]
}

After

hcl
resource "azurerm_key_vault_key" "example" {
  name         = "application-key"
  key_vault_id = azurerm_key_vault.example.id
  key_type     = "RSA-HSM"
  key_size     = 3072
  key_opts     = ["encrypt", "decrypt", "wrapKey", "unwrapKey"]
}

References