When you import a key into the Cryptographic Security Platform Vault for Cryptographic APIs, the target key must be wrapped with RSA-AES. To do this, first wrap the key with a temporary AES key, then wrap the temporary AES key with an RSA key. Concatenate the two wrapped keys and import them. If the key that you are importing was created in a different Cryptographic Security Platform Vault for Cryptographic APIs, then you can wrap that key before you export it with a key created in the new vault.

See below for the required steps.