You will need to create a new Cloud Service Provider account in the Cryptographic Security Platform Vault for Cloud Keys with cloud admin privileges for your AWS XKS deployment:

In the current release, a Cloud Service Provider account is tied to a single keyset.

To create a Cloud Service Provider Account for AWS XKS

  1. Log in to the Cryptographic Security Platform Vault for Cloud Keys webGUI using an account with Cloud Admin privileges.
  2. In the top menu bar, select CloudKeys.

  3. Select the CSP Accounts tab.
  4. Select Actions > Add Cloud Service Provider Account.
  5. On the Details tab, enter the account details. 

  6. Select Continue.

  7. On the Schedule tab, determine the rotation schedule for the access keys. This can be one of the following:

    • Never—The access keys will never be rotated.
    • Once a year—The access keys will be rotated once a year.
    • Every 6 months—The access keys will be rotated once every 6 months.
    • Every 30 days—Access keys will be rotated every 30 days.
    • Other—Access keys will rotate at the interval you select.
  8. Select Apply.

Name

The name you want to use for the Cloud Service Provider Account.

Description

An optional description of the Cloud Service Provider Account.

Admin Group

Select the Cloud Admin Group.

Type

Select AWS.

AWS Access Key ID

Enter the AWS Access Key ID.

AWS Secret Access Key

Enter the AWS Secret Access Key.

Default Region

Select the target region (the AWS XKS region) as the default region.