This section describes the workflow that occurs in the Cryptographic Security Platform Vault for Cloud Keys when you use BYOK for AWS.
To bring your own key
Vault creates a Cloud Key with key material. If HSM is configured, the key is generated and wrapped with a root key on the HSM.
AWS Key Management Service (KMS) creates a customer master key (CMK) with no key material associated.
Download the RSA-2048 wrapping public key and the import token from AWS KMS.
Import the RSA-2048 wrapping public key and the import token into Vault.
The imported wrapping key rewraps the symmetric key. If an HSM is configured, the HSM performs the wrapping.
Import the symmetric key into AWS KMS using the import token.
