Overview

<p class="shortdesc"></p> <p class="p">Customer master keys (CMKs) are the primary resources in Pind An Cloud KMS. A CMK contains the key ID, basic metadata (such as the key status), and the key material used to encrypt and decrypt data. </p> <p class="p">If you select to create a CMK with external key material, KMS generates a CMK without key material. The CMK is in the <span class="ph uicontrol">PENDING_IMPORT </span>status, and then you can import your own key material into it. </p> <p class="p">Generally, importing key material is applicable to the following scenarios: </p> <ul class="ul" id="overview__ul_tsv_h35_jlb"> <li class="li">You do not want to use the key material generated by Ping An Cloud KMS, but use your own key material and can delete it at any time. </li> <li class="li">When you accidentally delete your imported key material, you can re-import the same key material. </li> <li class="li">When you migrate local encrypted data to the cloud, you can import the key material on-premise to the cloud to use the same key material there. </li> </ul> <p class="p">When importing external key material, make sure: </p> <ul class="ul" id="overview__ul_usv_h35_jlb"> <li class="li">The key material is generated using a source of entropy that meets your requirements. </li> <li class="li">The imported key material is durable. Ping An Cloud can keep the imported key material highly available. However, it cannot guarantee that the durability of imported key material is at the same level as KMS generated key material. </li> </ul> <p class="p">The following figure describes how to import external key material. </p> <img class="image" id="overview__image_ycn_y35_jlb" src="https://obs-cn-shanghai.yun.pingan.com/pcp-portal/20200807112323-1467726b9164.png">
Did the above content solve your problem? Yes No
Please complete information!

Call us

400-151-8800

Email us

cloud@pingan.com

Online customer service

Instant reply

Technical Support

cloud products