Integrate BYOK for AWS Key Management Service and Entrust KeyControl

Create an AWS CSP account

  1. Sign in to the cloud keys vault URL created in Create a Cloud Keys Vault in the KeyControl.

  2. Select the CSP Accounts tab.

  3. In the Actions pull down menu, select Add CSP Account.

  4. In the Add CSP Account window, enter the Name and Description.

  5. In the Admin Group pull-down menu, select Cloud Admin Group.

  6. In the Type pull-down menu, select AWS.

  7. In the AWS Access Key ID text box, enter the Access key created in Create AWS AIM user.

  8. In the AWS Secret Access Key text box, enter the Secret access key created in Create AWS AIM user.

  9. In the Default region, choose your AWS region. Then select Continue.

    For example:

    keycontrol csp account 1
  10. In the Schedule tab, enter your organization’s standard rotation schedule for the access keys. Then select Apply.

    keycontrol csp account 2
  11. Notice the newly created CSP account.

    keycontrol csp account 3

Create a key set in KeyControl

  1. sign in to the cloud keys vault URL created in Create a Cloud Keys Vault in the KeyControl.

  2. Select the Key Sets tab.

  3. In the Actions pull down menu, select Create Key Set.

  4. In the Choose the type of keys in this key set: window, select AWS Key.

  5. In the Create Key Set window, enter a Name and Description. In the Admin Group pull-down menu, select Cloud Admin Group. Then select Continue.

    For example:

    keycontrol create keyset 1
  6. In the CSP Account tab, select the CSP account created in Create an AWS CSP account. Check Use as External Key Store to allow Entrust KeyControl to encrypt and decrypt the KMS keys. Then select Continue.

    For example:

    keycontrol create keyset 2
  7. In the HSM tab, check Enable HMS if an HSM is configured. Then select Continue.

    For example:

    keycontrol create keyset 3

    See Integrating with an HSM for additional information.

  8. In the Schedule tab, select a Rotation Schedule matching the selection made during Create an AWS CSP account. Then select Apply.

    For example:

    keycontrol create keyset 4
  9. Notice the newly created key set.

    For example:

    keycontrol create keyset 5

For further information, refer to Creating a Key Set in the KeyControl online documentation.