See below for configuring certificates and DNS for AWS XKS.

To configure certificates and DNS for AWS XKS

  1. In AWS, select a region geographically closest to the CSP Vault node.

  2. Install a public certificate on the Cryptographic Security Platform Vault node. 

    The certificate chain must include the intermediate and root CA.

  3. On your external/public DNS Server, add a DNS record for the CSP Vault node common name as specified in the certificate. 

    The FQDN in the DNS record must match the common name in the server certificate.

  4. Verify the server certificate, CA chain, and DNS record entries.