Adding an Amazon Web Service Key Management Service Server Using Access Information

You can add or modify an AWS Key Management Service (KMS) Server from the CommCell Console using the access information.

Before You Begin

  • The AWS KMS account that you configure must have the following permissions:

    • kms:CreateKey

    • kms:Decrypt

    • kms:DisableKeyRotation

    • kms:Encrypt

    • kms:ScheduleKeyDeletion

  • To use your own key, obtain the key ID provided by your key management service (KMS) provider after you import or generate the key using the KMS provider interface.

Procedure

  1. From the CommCell Console ribbon, on the Home tab, click Control Panel.

    The Control Panel window appears.

  2. Under Storage, click Key Management Servers.

    The Encryption Key Management Servers dialog box appears.

  3. Click Add, and then select AWS KMS.

    The Key Provider Properties dialog box appears.

  4. In the Key Provider Name box, enter a unique name for the key provider.

  5. From the Region list, select the region where AWS hosts the key management service.

  6. From the Authentication Type list, select one of the options - Access & Secret Keys or IAM Role Policy.

  7. If you selected Access & Secret Keys, then enter the following information:

    • In the Access Key box, enter the AWS access key.

    • In the Secret Access Key box, enter the AWS secret access key.

  8. To use access node, complete the following steps:

    1. Select Use Access Node checkbox.

      The Access Nodes area appears.

    2. Click Add.

      The Access Node dialog box appears.

    3. From the Access Node list, select the MediaAgent that you want to use as access node.

    4. For information about authentication, see steps 6 and 7 above.

    5. Click OK.

  9. To use your own key, complete the following steps:

    1. Click the Bring Your Own Keys tab.

    2. To enable Bring your Own Key (BYOK), select the Enable Bring Your Own Keys checkbox.

    3. To add a key, complete the following steps:

      1. Click Add.

        The Bring Your Own Key dialog box appears.

      2. Enter Key ID, and then click OK.

  10. Click OK.

Page contents

×

Loading...