See below for creating a CloudKey for DKE.
To create a CloudKey for DKE
Log in to the Cryptographic Security Platform Vault for Cloud Keys webGUI using an account with Cloud Admin privileges.
- In the top menu bar, click CloudKeys.
- Click the CloudKey tab.
- Select the Azure Key Set that you just created, and then select DKE Keys.
- Select Actions > Create CloudKey.
On the Details tab of the Create CloudKey dialog box, enter the following:
- Name–Enter the name for the CloudKey.
- Description–Enter the optional description for the CloudKey.
- Click Continue.
On the Access tab, enter the following:
Click Continue.
On the Schedule tab, determine the rotation schedule for the CloudKey. This can be one of the following:
- Inherit from Key Set—The CloudKey will use the Key Set's default schedule. If the Key Set schedule changes after you create the CloudKey, the CloudKey schedule will not update.
- Never—The CloudKey will never be rotated.
- Once a year—The CloudKey will be rotated once a year.
- Every 6 months—The CloudKey will rotate every 6 months.
- Every 30 days—The CloudKey will rotate every 30 days.
- Other—The CloudKey will be rotated at the interval you select.
- Click Apply.
Cipher
This can be one of the following:
- RSA-2048
- RSA-3072
- RSA-4096
DKE Cache
Enter the number of days to cache your RSA public key.
Azure Accounts
Select one of the followig:
- Allow All
- Specific Tenants (enter the tenant GUIDs to give access to the Azure accounts)