Integrate BYOK for AWS Key Management Service and KeyControl

Create a CSP account in KeyControl for AWS

  1. Sign in to the cloud keys vault URL created in Create a Cloud Keys Vault in the KeyControl.

  2. Select the CSP Accounts tab.

  3. In the Actions pull-down menu, select Add CSP Account.

  4. In the Add CSP Account window, enter the Name and Description.

  5. In the Admin Group pull-down menu, select Cloud Admin Group.

  6. In the Type pull-down menu, select AWS.

  7. In the AWS Access Key ID text box, enter the Access key created in create-aws-iam-user.adoc#create-aws-iam-user.

  8. In the AWS Secret Access Key text box, enter the Secret access key created in create-aws-iam-user.adoc#create-aws-iam-user.

  9. In the Default region, choose your AWS region. Then select Continue.

    For example:

    keycontrol csp account 1
  10. In the Schedule tab, enter your organization’s standard rotation schedule for the access keys. Then select Apply.

    keycontrol csp account 2
  11. Notice the newly created CSP account.

    keycontrol csp account 3

Test the CSP account connection to AWS

  1. Select the newly created CSP account.

  2. In the Actions pull-down menu, select Test Connection. The connection tested successfully pop-up windows appears.

    keycontrol csp account 4

Create a Key Set in KeyControl for AWS

  1. Sign in to the cloud keys vault URL created in Create a Cloud Keys Vault in the KeyControl.

  2. Select the Key Sets tab.

  3. In the Actions pull down menu, select Create Key Set.

  4. In the Choose the type of keys in this key set: window, select AWS Key.

  5. In the Create Key Set window, enter a Name and Description. In the Admin Group pull-down menu, select Cloud Admin Group. Then select Continue.

    For example:

    keycontrol create keyset 1
  6. In the CSP Account tab, select the CSP account created in Create a CSP account in KeyControl for AWS. Uncheck Use as External Key Store. Then select Continue.

    For example:

    keycontrol create keyset 2
  7. In the HSM tab, check Enable HMS if an HSM is configured. Then select Continue.

    For example:

    keycontrol create keyset 3

    See Integrating with an HSM for additional information.

  8. In the Schedule tab, select a Rotation Schedule. Then select Apply.

    For example:

    keycontrol create keyset 4
  9. Notice the newly created key set.

    For example:

    keycontrol create keyset 5

For further information, refer to Creating a Key Set in the KeyControl online documentation.