This is good to know. However, when I try to create a new cert database the only option I see is local.
I was following the instructions here:
https://www.ibm.com/docs/en/sva/10.0.7?topic=storage-configuring-network-hardware-security-module-hsm-support
Are there different instructions for the container version? Granted, I also don't have the IBM Security Verify Access SafeNet Luna Network HSM Extension installed, but how does that get installed in the container world if that is the issue?
PS: The binding of the IP address is what I had wondered was keeping back these solutions.
Thanks Scott!
Matt
------------------------------
Matt Jenkins
------------------------------
Original Message:
Sent: Sun June 02, 2024 05:03 PM
From: Scott Exton
Subject: IBM Security Verify Access on Containers utilizing HSMs
Mat,
The SafeNet Luna HSM device is actually supported in an ISVA containerised environment already.
The main factor which inhibits adoption of a HSM device in a containerised environment is that a lot of HSM devices require manual registration of the client IP address and binds an authentication token to that IP address. This works in an environment where the IP addresses of clients are static, but does not work well in a containerised environment. The SafeNet Luna HSM device doesn't bind a client to a specific IP address, which is why we can claim support for this HSM device.
I hope that this helps.
Scott A. Exton
Senior Software Engineer
Chief Programmer - IBM Security Verify Access
IBM Master Inventor