You must set permissions for the BYOK service by configuring each Azure Key Vault that you want to manage.
Azure Key Vault now offers Azure role-based access control (Azure RBAC) in addition to the previous access policy model. If you are upgrading from a previous Cryptographic Security Platform Vault release, you will have used the access policy model.
Setting permissions for the Azure RBAC permission model
Repeat the following steps for each key vault that uses the Azure RBAC permission model.
To set permissions for the Azure RBAC permission model
- Navigate to Azure > Key vaults > <Key Vault name> > Access control (IAM).
Click Add role assignment to assign the Key Vault Crypto Officer role to the BYOK application.
In Job function roles, select Key Vault Crypto Officer and then click Next.
Click + Select Members.
Search for the BYOK application and click the + next to it, then click Select.
Click Review + assign to move to the final step of Add role assignment.
Review the settings and then click Review + assign.
Setting permissions for Vault Access Policies
Repeat the following steps for each Key Vault that uses Vault Access Policies.
To set permissions for Vault Access Policies
- Navigate to Azure > Key vaults > <Key Vault name> > Access control (IAM).
- Use Add Access Policy to add permissions to the BYOK application.
- In the Key Permissions column, click Select All for both the Key Management Operations and Privileged Key Operations lists of permissions.
- Select Principal > BYOK application.
- Select Add.