See below for adding a Cloud Service Provider account for OCI (Oracle Cloud Infrastructure).

It may take up to 5 minutes for a new OCI API key to become active. If you attempt to create your Cloud Service Provider account before the API key is active, it will fail with the "Failed to validate Access Credentials OCI" error.

To add an account for OCI

  1. Log in to the Cryptographic Security Platform Vault for Cloud Keys webGUI using an account with Cloud Admin privileges.
  2. In the top menu bar, click CloudKeys.
  3. Click the CSP Accounts tab and select Actions > Add Cloud Service Provider Account.
  4. On the Details tab of the Add CSP dialog box, enter the account details. 

  5. Click Continue.

  6. On the Schedule tab, determine the rotation schedule for the access keys. 

    • Never
    • Every x days
    • Every x weeks
    • Every x months
    • Every x years
  7. Click Add.

Name

The name you want to use for the Cloud Service Provider Account.

Description

An optional description of the Cloud Service Provider Account.

Admin Group

Select the Admin Group that you want to use for the account.

Type

Select OCI.

OCI User ID

Copy the user information (everything after user=) from the configuration file preview.

OCI Tenancy ID

Copy the tenancy information (everything after tenancy=) from the configuration file preview.

OCI Region

Copy the region information (everything after region=) from the configuration file preview.

OCI API Key Fingerprint

Copy the fingerprint information (everything after fingerprint=) from the configuration file preview.

OCI API Key Content

Click Load File to upload the key file that you generated.

OCI API Key Passphrase

If you generated an RSA Key Pair with a passphrase, enter the passphrase here.

OCI Storage Bucket

If you are using a virtual private vault, enter the bucket name. This is where backups of HSM-protected keys in a virtual private vault will be stored.

 If you have a virtual private vault, imported keys will not be stored in the Cryptographic Security Platform Vault for Cloud Keys.

OCI Storage Namespace

If you are using a virtual private vault, enter the storage bucket namespace.