If the password verification attempts are passed through directly to the HSM, then yes, this is standard.