The Cryptographic Security Platform Vault for Cloud Keys lets you manage keys for use with providers such as AWS, Azure, and GCP in Bring Your Own Key (BYOK) and Hold Your Own Key (HYOK) environments. You can use Cryptographic Security Platform Vault as
- External Key Store (XKS) for AWS,
- External service for Double Key Encryption (DKE),
- External Key Manager (EKM) provider
See below for the required steps.
- Managing Cloud Service Provider accounts
- Managing key sets
- Managing CloudKeys
- Managing Vault BYOK
- Managing AWS XKS
- Using CSP Vault as a GCP EKM Provider
- Using double key encryption with Vault
- Managing Authentication for Vault for Cloud Keys
If you plan to manage Elliptic Curve Cryptography (ECC) keys in a Cryptographic Security Platform Vault for Cloud Keys that is protected by an nShield HSM, the ECC feature must be enabled on the HSM.