See below for creating a CloudKey for AWS.
To create a CloudKey for AWS
Log in to the Vault web GUI using an account with Cloud Admin privileges.
- In the top menu bar, click CloudKeys.
Click the CloudKeys tab and select the Key Set and Region.
If you do not complete the selections on the CloudKeys page, add them on the Details tab of the Create CloudKey dialog box.
- Select Actions > Create CloudKey.
On the Details tab of the Create CloudKey dialog box, enter the following:
- Create as Multi-Region Key—Check the Multi-Region checkbox if you are using AWS Multi-Region keys. Otherwise, leave it unchecked.
- Region—If you selected Multi-Region, this field changes to the Primary Region. If you did not finish selecting the key set prompts, select the region here.
- Name—Enter the name for the CloudKey.
- Description—Enter the optional description for the CloudKey
- Click Continue.
On the Purpose tab, complete the following:
- Click Continue.
On the Access tab, enter the following:
- Administrators—Choose the users who have administrative rights to the CloudKey.
- Users—Choose the users who can use the CloudKey for encryption or decryption.
On the Schedule tab, set the CloudKey rotation schedule. This can be one of the following:
- Inherit from Key Set—The CloudKey will use the default schedule from the Key Set. If the Key Set schedule changes after you create the CloudKey, the CloudKey schedule will not update.
- Never—The CloudKey will never be rotated.
- Once a year—The CloudKey will be rotated once a year.
- Every 6 months—The CloudKey will rotate every 6 months.
- Every 30 days—The CloudKey will rotate every 30 days.
- Other—The CloudKey will be rotated at the interval you select.
Choose when this CloudKey version should expire. The per-version expiration can be one of the following:
- Never—The CloudKey version will never expire.
- Fixed Date—All CloudKey versions will expire on the date that you set.
- Relative Expiry—Each CloudKey version will expire after the number of days that you set.
Choose when the CloudKey should expire. This can be Never, or you can choose a specific date.
If you selected an expiration date, choose the Expire Action to define what happens to the CloudKey when it expires. This can be one of the following:
Disable—The key will remain in the cloud, but is disabled and cannot be used by any applications.
Delete—The key is disabled in the cloud and cannot be used by any applications. You can set the date for permanent deletion.
Delete from Cloud—Removes the key material from the KMS, and applications can no longer use this key from the cloud. However, the Cryptographic Security Platform Vault retains a copy of the key, which you can upload back to the cloud.
- Click Apply.
Purpose
This can be one of the following:
- Symmetric Encrypt and decrypt
- Generate and verify MAC
- Asymmetric Encrypt and decrypt
- Asymmetric Sign and verify
- Use on-demand key rotation for new versions (for AES keys only)
Algorithm
Choose the algorithm that matches the purpose you selected. T
- For Symmetric Encrypt and decrypt or On-demand key rotation:
- AES-256
- For Generate and verify MAC:
- HMAC - SHA224 Digest
- HMAC - SHA256 Digest
- HMAC - SHA384 Digest
- HMAC - SHA512 Digest
- For asymmetric encryption and decryption:
- 2048-bit RSA
- 3072-bit RSA
- 4096-bit RSA
- For asymmetric signing and verification:
- Elliptic Curve P-256
- Elliptic Curve P-384
- Elliptic Curve P-521
- Elliptic Curve secp256k1
- 2048-bit RSA
- 3072-bit RSA
- 4096-bit RSA