Supported Mechanisms

This chapter provides information about the supported PKCS#11 standard mechanisms and the Thales-proprietary mechanisms supported in all released versions of the Luna HSMLuna USB HSM 7 firmware. Refer to the page that applies to your installed firmware version.

The individual mechanism pages provide additional information about using each mechanism. You can also compare the attributes/requirements of each mechanism across different firmware versions.

NOTE   With firmware version 7.9.3 and newer, the Luna Backup HSM 7 can use any cryptographic algorithms used for secure cloning (CPv4) of keys and objects, including PQC/quantum-safe algorithms. The backup HSM recognizes, and can backup/restore, all the same mechanisms and key types that are available to the Luna General Purpose HSMs (GPHSM) of equivalent firmware versions. All Luna form factors support Post Quantum Cryptography (PQC) for secure generation and usage of keys along with backup and restore.

>Firmware 7.9.3 Mechanisms

>Firmware 7.9.2 Mechanisms

>Firmware 7.9.1 Mechanisms

>Firmware 7.9.0 Mechanisms

>Firmware 7.8.9 Mechanisms

>Firmware 7.8.7 Mechanisms

>Firmware 7.8.5 Mechanisms

>Firmware 7.8.4 Mechanisms

>Firmware 7.8.2 Mechanisms

>Firmware 7.8.1 Mechanisms

>Firmware 7.8.0 Mechanisms

>Firmware 7.7.2 Mechanisms

>Firmware 7.7.1 Mechanisms

>Firmware 7.7.0 Mechanisms

>Firmware 7.4.2 Mechanisms

>Firmware 7.4.0 Mechanisms

>Firmware 7.3.3 Mechanisms

>Firmware 7.3.0 Mechanisms

>Firmware 7.2.0 Mechanisms

>Firmware 7.1.0 Mechanisms

>Firmware 7.0.3 Mechanisms

>Firmware 7.0.2 Mechanisms

>Firmware 7.0.1 Mechanisms

If you are using RSA keys in FIPS mode, refer to RSA Mechanism Remap for FIPS Compliance for information about remapping your mechanisms to maintain FIPS compliance. This applies to Luna HSM Client 7.4.0 and older.

NOTE   Starting with Luna HSM Firmware 7.7.0, the tables linked above include a column that specifies any operations that are restricted when the HSM is in FIPS mode.