Upload coordinated external keys using VPC to store them in your crypto space. You can manage most coordinated external keys in Google Cloud using
- Google Cloud console
- gcloud CLI
- Cloud KMS API
- Cloud KMS client libraries
- Procedure
To create coordinated EKM CloudKeys
Log in to the Cryptographic Security Platform Vault for Cloud Keys webGUI using an account with Cloud Admin privileges.
- In the top menu bar, click CloudKeys.
Create a Cloud Service Provider account and a KeySet.
The KeySet UUID becomes the crypto space ID.
The Crypto Space Path is displayed on the Key Sets details tab:
v5/cryptospaces/<keyset_uuid>
Create an EKM connection in the Google Cloud console
Set the EKM management node to Cloud KMS.
During setup, authorize your Google Cloud project service account to access your crypto space in CSP Vault for Cloud Keys using the EKM access control list in the Cloud Service Provider account.
For more information on creating an EKM connection, see https://cloud.google.com/kms/docs/create-ekm-connection
Optionally, create a Key Access Justification policy in the Cloud Service Provider account.