Create CMKs

You can use the Ping An Cloud KMS console to create CMKs.

About this task

CMKs are master keys you create with Ping An Cloud KMS. You can use them to encrypt and decrypt data keys, and generate envelopes. You can also use them to directly encrypt and decrypt small amounts of data.

Procedure

  1. Log in to the Key Management Service Console .
  2. In the left navigation pane, click Keys > Customer managed keys.
  3. On the Customer managed keys page, click +Create in the upper-right corner.
  4. On the Create Key page, configure a CMK by completing the following information.
    • Purpose: ENCRYPTE/DECRYPT by default.
    • Currently Selected Area: Select the region of the CMK.
    • Alias: Alias of the CMK. Using an alias to refer to a CMK can help you to identify different CMKs.
    • Description: Description about the CMK. For example, you can enter information about the data or applications you want to protect using the CMK.

    Click Advanced Options. On the page that expands, you can select the origin of key material and the encryption standard.

    • Key Material Source:
      • PingAn Cloud KMS: Ping An Cloud generated CMKs.

      • External: Ping An Cloud KMS does not generate key material for the CMK and you can import external key material. For more information, see Import Key Material.

    • Encryption standard: Select International standard (256 bits or 128 bits).
  5. Click Confirm.

Results

  • When you create a CMK, if the selected key material origin is PingAn Cloud KMS, KMS generates a CMK in the ENABLE status. It is displayed in the Keys area.

  • When you create a CMK, if the selected key material origin is External, KMS generates a CMK in the PENDING_IMPORT status with no key material. You can import your own key material into that CMK.

Did the above content solve your problem? Yes No
Please complete information!

Call us

400-151-8800

Email us

cloud@pingan.com

Online customer service

Instant reply

Technical Support

cloud products