Create a CloudKey in the AWS XKS Key Set you created earlier.
AWS services use this CloudKey to encrypt objects in AWS.
To create a CloudKey for AWS XKS
- Log in to the Vault web GUI using an account with Cloud Admin privileges.
- In the top menu bar, select CloudKeys.
- Select the CloudKeys tab.
- From the Key Set menu, select the AWS XKS Key Set that you created earlier.
Select Actions > Create CloudKey.
On the Details tab, enter the following:
- Region—Select the AWS XKS region.
- Name—Enter the name for the CloudKey.
- Description—Enter the optional description for the CloudKey.
- Click Continue.
On the Access tab, enter the following.
- Administrators—Choose the users who have administrative rights to the CloudKey.
- Users—Choose the users who can use the CloudKey for encryption or decryption.
- Click Continue.
On the Schedule tab, determine the rotation schedule for the CloudKey. This can be one of the following:
- Inherit from Key Set—The CloudKey will use the Key Set's default schedule. If the Key Set schedule changes after you create the CloudKey, the CloudKey schedule will not update.
- Never—The CloudKey will never be rotated.
- Once a year—The CloudKey will be rotated once a year.
- Every 6 months—The CloudKey will rotate every 6 months.
- Every 30 days—AWS will rotate the CloudKey every 30 days.
- Other—Rotate the CloudKey at the interval you select.
- Click Apply.