Skip to main content

Proxy User

CloudHSM uses a reverse proxy to control access to CloudHSM on a network layer. Every CloudHSM subscriber is assigned a proxy user (also called service user) to authenticate against the proxy.

Proxy Username and Password

You received the proxy username and proxy password when you signed up to CloudHSM, as part of the credentials file. Configure the proxy username and proxy password in your API provider.

If you have lost the credentials file or require credential rotation, please open a Support Ticket from a "Privileged Support User" account. Securosys will then issue new proxy credentials for you. This is subject to a cost. After you have confirmed that the new credentials have been installed in all your applications, Securosys will revoke the old credentials.

IP Allowlisting

The proxy supports IP-based allowlisting to restrict CloudHSM access on a network layer. During sign-up, you can specify a comma-separated list of source IPv4 addresses that you want to allow. You can specify a subnet to allow a range of addresses. If you leave this empty, any source IP will be allowed.

192.0.2.0/24, 198.51.100.2/32, 203.10.113.3

Each HSM Partition has its own IP allow-list.

To request changes to the allowlist, please open a Support Ticket from a "Privileged Support User" account. Securosys will then apply the change to the proxy. This is subject to a cost.

Scope

The IP allowlist applies to the HSM (HSMaaS) and to dedicated TSB instances (dedicated TSBaaS).

The allowlist does not apply to the main, shared TSB instance (TSBaaS). If you require IP allowlisting for the TSB, please contact Securosys to purchase a dedicated hosted TSB.

Get started withCloudHSM for free.
Other questions?Ask Sales.
Feedback
Need help?