See below to export any key from a Vault for Cryptographic APIs (Export-Vault) and then import it into a different one (Import-Vault). 

Export-Vault and Import-Vault can be different versions, as long as both are version 10.4.5 or later and support the target key type.

To import a key from a different Cryptographic API

  1. Log in to the Import-Vault web GUI.

  2. Create an RSA-2048 key in the web GUI.

  3. Select the key that you created, and click Download Public Key to download the public part of the RSA-2048 key. 

  4. In a different browser window, log into the Export-Vault web GUI.

  5. From the Home tab, select Manage > Keys.

  6. On the Manage Keys page, select the RSA-2048 key that you want to export and select Actions > Export Key.

  7. Click Download Key. The RSA-2048 key from the Export-Vault is now wrapped by the Import-Vault wrapping key and downloaded.

  8. Return to the Import-Vault web GUI.

  9. From the Home tab, select Manage > Keys.

  10. On the Manage Keys page, select Actions > Import Key.

  11. On the Import Key page, complete the following. 

    Field

    Description

    Name

    Enter the new name for the key that you exported.

    Description

    Enter the optional description for the key that you exported.

    Algorithm

    Select AES.

    Key Length

    Select 256.

    Key Material

    Select the wrapped AES key that you exported.

    Wrapping Key

    Select the RSA-2048 public key that you used to wrap the AES key.

    Wrapping Key Version

    Select the version of the key that you exported.

    Hashing Algorithm

    Select SHA1.

  12. Click Import Key.