The following limitations currently exist: 

  • AWS currently supports only 256-bit AES keys.

  • Amazon recommends a round-trip time latency of under 35 milliseconds between the AWS region and the CSP Vault.

  • The maximum request timeout in KMS is set to 250 milliseconds.

  • External key stores are supported in MOST AWS Regions in which AWS KMS is supported. Prior to selecting the region, make sure XKS is supported in that region.

  • Only the XKS Public endpoint connection option is supported.