Using Key Protect
Business Automation Content Services on Cloud supports IBM® Key Protect for the lifecycle management of encryption keys that are used in IBM Cloud services or client-built applications.
Key Protect provides
roots of trust (RoT), backed by a hardware security module (HSM).
For more information about Key Protect,
see the corresponding entry in the IBM Cloud Catalog
.
If Key Protect is
enabled on your subscription, the Content Platform Engine domain
master key and the content encryption key for the pre-provisioned
storage area are automatically generated and saved to your Key Protect service
instance. Review the following guidelines about the master key and
content encryption key:
- Do not rotate or delete the domain master key. This key is used to encrypt Content Platform Engine user credentials, user name, and passwords for various purposes that include access to external services and devices.
- Do not delete your existing content encryption keys. These keys are used to encrypt and decrypt your content when it is stored or retrieved. Missing content encryption keys cause content encryption, decryption, and retrieval to fail.
- Lock the service ID and API key that are associated with your Key Protect service instance. This action helps ensure that you don't accidentally delete your service ID or API key.
- As a best practice, generate a new content encryption key regularly.
For more information about generating a new content encryption key,
see Encrypting content
.