Description
Key Vault supports software-protected and HSM-protected keys. When HSM protection is required, the Premium tier supports RSA-HSM or EC-HSM to perform key operations within a hardware security boundary.
Potential impact
Software-protected keys may not meet an organizational or regulatory requirement for HSM protection.
Remediation
Confirm the need for HSM protection and choose a supported key type and algorithm. Changing key_type recreates the key resource, so plan continued decryption of existing data and consumer migration first.
Examples
The examples use RSA-HSM. The referenced Key Vault must use the Premium tier.
Before
hcl
resource "azurerm_key_vault_key" "example" {
name = "application-key"
key_vault_id = azurerm_key_vault.example.id
key_type = "RSA"
key_size = 3072
key_opts = ["encrypt", "decrypt", "wrapKey", "unwrapKey"]
}
After
hcl
resource "azurerm_key_vault_key" "example" {
name = "application-key"
key_vault_id = azurerm_key_vault.example.id
key_type = "RSA-HSM"
key_size = 3072
key_opts = ["encrypt", "decrypt", "wrapKey", "unwrapKey"]
}