Create a CloudKey in the AWS XKS Key Set you created earlier. 

AWS services use this CloudKey to encrypt objects in AWS.

To create a CloudKey for AWS XKS

  1. Log in to the Vault web GUI using an account with Cloud Admin privileges.
  2. In the top menu bar, select CloudKeys.
  3. Select the CloudKeys tab.
  4. From the Key Set menu, select the AWS XKS Key Set that you created earlier.
  5. Select Actions > Create CloudKey.

  6. On the Details tab, enter the following: 

    • Region—Select the AWS XKS region.
    • Name—Enter the name for the CloudKey.
    • Description—Enter the optional description for the CloudKey.
  7. Click Continue. 
  8. On the Access tab, enter the following.

    • Administrators—Choose the users who have administrative rights to the CloudKey.
    • Users—Choose the users who can use the CloudKey for encryption or decryption.
  9. Click Continue.
  10. On the Schedule tab, determine the rotation schedule for the CloudKey. This can be one of the following: 

    • Inherit from Key Set—The CloudKey will use the Key Set's default schedule. If the Key Set schedule changes after you create the CloudKey, the CloudKey schedule will not update.
    • Never—The CloudKey will never be rotated.
    • Once a year—The CloudKey will be rotated once a year.
    • Every 6 months—The CloudKey will rotate every 6 months.
    • Every 30 days—AWS will rotate the CloudKey every 30 days.
    • Other—Rotate the CloudKey at the interval you select.
  11. Click Apply.