Luna HSM Firmware 7.7.0
Luna HSM firmware 7.7.0 was released in October 2020.
>Download Luna Network HSM Appliance Software 7.7.0 (includes firmware update to Luna HSM Firmware 7.7.0)
Refer to NIST certificate #4090 for FIPS 140-2 Level 3 certification:
This is the most recent firmware version certified under the Common Criteria standard. The certificates are posted here:
>CC Certificate -- Thales Luna K7 HSM
This release is certified under the eIDAS standard and the certificate is posted here:
New Features and Enhancements
Luna HSM firmware 7.7.0 includes the following new features and enhancements:
Scalable Key Storage
Scalable Key Storage is an optional feature that allows off-board storage of keys and objects in quantities greater than the capacity of an HSM - virtually unlimited storage, for use with your RSS (Remote Signing and Sealing) and other applications that require thousands or millions of keys. An SKS Master Key (SMK, which never leaves the HSM) securely encrypts extracted keys and objects, such that they remain within the HSM's security envelope, and can be reinserted (decrypted inside the HSM) for immediate use by your application.
Preserves key attributes through the life-cycle of a key.
Provides the option of new SKS function, or classic Luna "keys always in hardware" operation, on a partition-by-partition basis.
This feature also requires
Per-Key Authorization allows granular control of key material for applications requiring high assurance by providing authorization on a per-key basis.
This feature also requires
Valid Update Paths
You can update the Luna HSM firmware to version 7.7.0 from the following previous versions:
>7.0.1, 7.0.2, 7.0.3, 7.1.0, 7.2.0, 7.3.0, 7.3.3, 7.4.0
Special Considerations for Luna HSM Firmware 7.7.0 and Newer
Luna HSM Firmware 7.7.0 introduces new capabilities, features, and other significant changes that affect the operation of the HSM. Due to some of these changes, you must be aware of some special considerations before updating to Luna HSM Firmware 7.7.0 or newer. For more information, refer to Special Considerations for Luna HSM Firmware 7.7.0 and Newer before proceeding with the update.
This section highlights important issues you should be aware of before deploying HSM firmware 7.7.0.
FIPS Restrictions in Luna HSM Firmware 7.7.0 and Newer
New restrictions have been added to some mechanisms when the HSM is in FIPS mode (HSM policy 12: Allow non-FIPS Algorithms set to OFF), to comply with FIPS SP800-131a Rev2 published in March 2019.
The following mechanisms are not permitted to wrap objects in FIPS mode (unwrap operations are permitted):
The following mechanisms are not permitted to sign data in FIPS mode (verify operations are permitted):