Azure Key Vault Managed HSM - Security Domain Certificate Renewal

Jonathan Maas 20 Reputation points
2025-01-03T18:59:56.7666667+00:00

As documented by Azure, when activating an Azure Key Vault Managed HSM resource you must create a security domain by sending at least three RSA public keys to the HSM. My question is do the certificates/keys need to be updated prior to their set expiration date for the HSM to continue functioning? If so is there any documentation around this process? I wasn't finding any documentation or any Powershell commands that would address updating domain security certificates.

https://learn.microsoft.com/en-us/azure/key-vault/managed-hsm/quick-create-powershell#activate-your-managed-hsm

Azure Key Vault
Azure Key Vault
An Azure service that is used to manage and protect cryptographic keys and other secrets used by cloud apps and services.
1,350 questions
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.