See below for creating a key set.
To create a key set
Log in to the Vault web GUI using an account with Cloud Admin privileges.
- In the top menu bar, click CloudKeys.
Click the Key Sets tab.
Select the type of key to be contained in the Key Set. This can be one of the following:
AWS Key
Azure Key
GCP Key
OCI Key
SFDC Key
On the Details tab of the Create Key Set dialog box, enter the following:
- Name—Enter the name for the Key Set.
- Description—Enter the optional description for the Key Set.
- Admin Group—Select the Admin Group.
Choose whether or not you want to enable audit logging for HYOK, EKM, and XKS operations.
Enabling audit logging for these operations could affect performance. Please be aware before you enable this. You can enable or disable this feature at any time from the Key Set Details tab.
- Click Continue.
On the Cloud Service Provider Account tag, choose an existing Cloud Service Provider Account or add a new account to use with this Key Set.
Check the Yes, import all keys checkbox to import all pre-existing Customer Managed Keys (CMKs) in the Cloud Service Provider Account.
If your imported keys are deleted in the CSP, they cannot be restored by Cryptographic Security Platform Vault.
Click Continue.
On the HSM tab, check the Enable HSM checkbox if you plan to use an HSM to create CloudKeys that can be uploaded to the cloud.
Once the key material is in the KMS, you no longer need the HSM. However, if you remove the CloudKey from the cloud, you will need to use the HSM to upload the key again.
If you selected Enable HSM, click Verify HSM connection to test the connectivity and suitability of the configured HSM. Cryptographic Security Platform Vault checks whether the HSM is accessible and supports creating and exporting relevant keys.
Some HSM servers with older firmware versions do not support key creation and wrapping. If the connection test fails, check the HSM server's firmware version. If it is old, update it to the latest version.
Click Continue.
On the Schedule tab, determine the default rotation schedule for the CloudKeys created in this Key Set. This can be one of the following:
- Never
- Once a year
- Every 6 months
- Every 30 days
- Other
- Click Apply.