See below for creating a CloudKey for Azure.
To create a CloudKey for Azure
Log in to the Vault web GUI using an account with Cloud Admin privileges.
- In the top menu bar, click CloudKeys.
Click the CloudKeys tab
Select the Key Set and the Type.
- Select Actions > Create CloudKey.
On the Details tab of the Create CloudKey dialog box, enter the following:
Key Vault or Managed HSM—If you did not finish selecting the Key Set prompts, you will need to select the Key Vault or Managed HSM here.
- Create as Multi-Vault Key—Select this option if you want this CloudKey to be available in multiple vaults. Otherwise, leave it unchecked.
- Name—Enter the name for the CloudKey.
- Description—Enter the optional description for the CloudKey
Click Continue.
On the Access tab, enter the following:
- Hardware Protected—Select whether or not to create a hardware-protected key in Azure. For premium vaults only. This field is visible only for CloudKeys of type Key Vault and DKE.
- Cipher—Select the RSA or EC key that you want to use. For DKE keys, only RSA is supported.
- Permitted operations (for Key Vault only)—Check the checkboxes for the allowed key operations.
- Azure Accounts (for DKE Keys only)—Select Allow all or Specific tenants.
Click Continue.
On the Schedule tab, determine the rotation schedule for the CloudKey. This can be one of the following:
- Inherit from Key Set—The CloudKey will use the Key Set's default schedule. If the Key Set schedule changes after you create the CloudKey, the CloudKey schedule will not update.
- Never—The CloudKey will never be rotated.
- Once a year—The CloudKey will be rotated once a year.
- Every 6 months—The CloudKey will rotate every 6 months.
- Every 30 days—The CloudKey will rotate every 30 days.
- Other—The CloudKey will be rotated at the interval you select.
Select the Activation Date for the CloudKey.
Choose when this CloudKey version should expire. The per-version expiration can be one of the following:
- Never—The CloudKey version will never expire.
- Fixed Date—All CloudKey versions will expire on the date that you set.
- Relative Expiry—Each CloudKey version will expire after the number of days that you set.
Choose when the CloudKey should expire. This can be Never, or you can choose a specific future date for all versions of the key to expire.
For Azure CloudKeys, once you set an expiration date, you can not change the value back to Never.
If you selected an expiration date, choose the Expire Action to define what happens to the CloudKey when it expires. This can be one of the following:
Disable—The key will remain in the cloud, but is disabled and cannot be used by any applications.
Delete—The key is disabled in the cloud and cannot be used by any applications. You can set the date for permanent deletion.
Delete from Cloud—Removes the key material from the KMS, and applications can no longer use this key from the cloud. However, Cryptographic Security Platform Vault retains a copy of the key which can be uploaded back to the cloud.
- Click Apply.