See below for creating a key set for AWS XKS.
To create a key set for AWS XKS
- Log in to the Vault web GUI using an account with Cloud Admin privileges.
- In the top menu bar, select CloudKeys.
- Select the Key Sets tab and select Actions > Create Key Set.
Select AWS Key as the key set type.
On the Details tab of the Create Key Set dialog box, enter the following:
- Name—Enter the name for the key set.
- Description—Enter the optional description for the key set.
- Admin Group—Select Cloud Admin Group.
- Click Continue.
On the Cloud Service Provider Account tab, enter the following:
- Cloud Service Provider Account—Select the newly created Cloud Service Provider account to use with this key set.
- Enable External Key Store—Select Enable External Key Store
- Copy the AWS XKS Access Key ID and Secret Access Key to a notepad.
Select Continue.
On the HSM tab, you can optionally enable an HSM.
Select Continue.
On the Schedule tab, determine the default rotation schedule for the CloudKeys created in this Key Set. This can be one of the following:
- Never—The CloudKey will never be rotated.
- Once a year—The CloudKey will be rotated once a year.
- Every 6 months—The CloudKey will be rotated once every 6 months.
- Every 30 days—The CloudKey will rotate every 30 days.
- Other—The CloudKey will be rotated at the interval you select.
Click Apply.