Setting up for keys
In order to be able to use EKMF Web to manage keys in various services, the following steps are generally required:
- You first need to create an instance of that service, or install an agent (e.g. KMG Agent on System z).
- You then need to create a connection to those services in EKMF Web, which are referred to as Keystores or Keystore connections throughout this document and the user interface.
- The last step is to create a key template that specifies the characteristics of the keys to be created, like naming conventions, key algorithm and key length.
Supported keystores
EKMF Web supports the following keystores:
EKMF Web V2.0:
- KMG Agent for keys on z/OS that can be used for Pervasive Encryption
EKMF Web V2.1:
- IBM® Key Protect
- Amazon® Web Services Key Management System
- Azure® Key Vault two variants permium and standard.