You can add or modify a Microsoft Azure Key Vault server with Bring your Own Key (BYOK) support from the CommCell Console.
Before You Begin
- Obtain the key ID provided by your key management service (KMS) provider after you import or generate the key using the KMS provider interface. The key ID must be in the following format: keyid/version ID.
Procedure
-
Create an Azure Key Vault server without access node or with access node.
-
On the Key Provider Properties dialog box, complete the following steps:
-
Click the Bring Your Own Keys tab.
-
To enable Bring your Own Key (BYOK), select the Enable Bring Your Own Keys checkbox.
-
To add a key, complete the following steps:
-
Click Add.
The Bring Your Own Key dialog box appears.
-
Enter Key ID, and then click OK.
-
-
-
Click OK.
Results
The Key Vault server appears in the Encryption Key Management Servers dialog box.