DPoD IDP Migration and Luna Cloud HSM Client Network Connectivity

Early in 2025 Thales Data Protection on Demand (DPoD) will be changing the Identity Provider (IDP) used in the DPoD platform to Thales OneWelcome. To ensure continued network connectivity between your Luna Cloud HSM client and the service partition please ensure that you update your include lists to allow the Thales OneWelcome fully qualified domain names. The Luna Cloud HSM data centers are configured with floating IP addresses and as a result of this configuration we do not support using static IP addresses or hardcoded IP addresses to access the services. 

For more information about the IDP migration see the DPoD IDP Migration FAQ. For more information about configuring and troubleshooting your client connection see Client Network Connectivity and Troubleshooting the Client Connection.

Public List Pricing Now Available

Thales is pleased to announce that public list pricing for the Data Protection on Demand (DPoD) marketplace is now available. This means you can easily view list prices for our growing range of market-leading Thales Data Security solutions, including Luna HSM, CipherTrust Data Security Platform and payShield HSM. 

Pricing: 

Pricing is available for all Thales services, and the list prices are now visible on the marketplace. For those services that offer more than one plan, the pricing stated includes the basic plan.  For partner services, please contact the relevant partners. Please note that our online list pricing is currently displayed in Euros only, other currencies are to follow later. Thales continues to offer DPoD services in a range of currencies and, billing and quoting can be completed in your preferred currency. Simply contact us, and we will provide you with a customized quote for your specific needs and location. 

Billing Options: 

As a reminder, DPoD offers flexible billing plans to meet your specific data protection needs. Choose from Full Upfront, Annual Upfront and Monthly Arrears billing when quoting DPoD options. 

Try Before You Buy: 

Remember, before you sign up take advantage of our free trials and experience the power of the DPoD marketplace firsthand. Test our solutions without commitment and see how they can help you protect your data. 

For more information see the Thales DPoD Marketplace.

DPoD IDP Migration

Thales Data Protection on Demand (DPoD) will be changing the Identity Provider (IDP) used in the DPoD platform to Thales OneWelcome. This update enables the platform to provide modern authentication options as well as simplifying logins for users that manage multiple tenants on the platform. 

For more information about this upcoming change and potential impacts to you please see the DPoD IDP Migration FAQ.

Luna Cloud HSM Releases Plugin 2.5.0 GA with the 10.7.2 Client

Plugin version 2.5.0 with the HSM client 10.7.2 is now available for download from Thales Data Protection on Demand for Luna Cloud HSM services.

See Upgrade Client for more information about upgrading your client.

Users are encouraged to upgrade to this latest client version and ensure it is supported in accordance with the Universal Client Supported Versions with Luna Cloud HSM table.

Added 

Luna client uses the existing config file

Customers can use the client without having to configure the "ChrystokiConfigurationPath" environment variable first.

Grouping startup for P11 commands in the plugin

The client startup time was very slow. To address this issue we now group the P11 commands together and send them as one to reduce the turnaround time.

Changed

- Using 10.7.2 or higher, users are no longer required to run setenv to configure the client to connect to the Luna Cloud HSM Service. However, setenv may still be used to configure the client for hybrid use cases or integrations where setting the ChrystokiConfigurationPath is required.
Please see Unpack the client for more information.

- Users can connect to a Luna Cloud HSM service by running the Luna Client in a docker container.
Please see Create a Docker Container to Access a Luna Cloud HSM Service for more information.

- A number of enhancements has been added to the LCH support tool. 
The support tool now creates an output file containing additional logging generated by running lunacm. It will also tell you the file was created, its name and the amount of time taken to run each test.
Please see Client connectivity support tool for more information.

Audit Logs available through tenant user interface

Thales Data Protection on Demand (DPoD) audit logs for Luna Cloud HSM and CipherTrust Data Security Platform as a Service (CDSPaaS) service instances are now available through the tenant user interface. You can generate, review, and download audit logs for services in your tenant using your tenants Logs page. For more information about viewing and downloading audit logs through the tenant user interface see Audit Logging.


Deprecation of CPv1 Cloning

In the upcoming release of FW 3.0 for Luna Cloud HSM, CPv1 will be removed from FIPS firmware support as it is no longer compliant with 140-3. As this only affects FIPS mode, all affected users should use CPv4 or transition service to non-FIPS mode. If Luna Network HSM users want to clone to Luna Cloud HSM with a FIPS partition they will have to use Luna 7.8 or higher. See Universal Cloning for more information.

Client Upgrade Required for Luna Cloud HSM Services

In advance of upcoming enhancements to Luna Cloud HSM we wish to remind our customer base that client versions 10.2, 10.3 and 10.4 are no longer supported by the service and must be upgraded.

Although these client versions will continue to function today, future upgrades to the Cloud HSM Service will render them inoperable.

Users must upgrade to a supported client version before August 27, 2024.

Full instructions for upgrading the client can be found in the thalesdocs.com documentation; https://thalesdocs.com/dpod/services/luna_cloud_hsm/client/upgrade/index.html

For more details please visit our Customer Support Portal.

Show Previous EntriesShow Previous Entries