Configuring access to KMS by using Thales CipherTrust Manager
Configure Thales CipherTrust Manager to provide secure key management by creating the required KMIP clients and interfaces, and generating the Key Encryption Key (KEK) for storageclass encryption.
Before you begin
-
Create a KMIP client if one does not exist.
- From the user interface, select .
- Add the
CipherTrustusername to the Common Name field during profile creation.
-
Go to to create a token.
Copy the token for the next step.
-
To register the client, go to .
- Specify the Name.
- Paste the Registration Token from the previous step, and click Save.
- Download the private key and client certificate by clicking Save Private Key and Save Certificate, respectively.
-
To create a new KMIP interface, go to .
- Select KMIP Key Management Interoperability Protocol, and click Next.
- Select a free Port.
- Select Network Interface to all.
- Select Interface Mode as TLS, verify client cert, user name taken from client cert, auth request is optional.
-
(Optional) Enable hard delete to delete both metadata and material when the key is deleted.
This option is disabled by default.
- Select the CA to use, and click Save.
- To get the server CA certificate, click the Action menu (⋮) next to the newly created interface, and click Download Certificate.
Procedure
- Go to .
- Enter Key Name.
- Set Algorithm to AES and Size to 256.
- Enable Create a key in Pre-Active state, and set the date and time for activation.
- Ensure that Encrypt and Decrypt are enabled under Key Usage.
- Copy the ID of the newly created key to use as the unique identifier during deployment.