Getting started with BYOK for AWS
This quickstart guide provides an overview of using the Bring Your Own Key (BYOK) process for AWS Key Management Service (KMS).
Installation
- Configure the necessary settings on the HSM. For CloudHSM, this is managed for you by Securosys.
- Install the Primus Tools.
Bring your key to AWS
- Create an AWS KMS key with no key material.
- Download the public key and import token.
- Create a key on the Securosys CloudHSM or Primus HSM to be used for BYOK.
- Export and wrap the key with the public key downloaded from AWS.
- Import the key into AWS KMS.
AWS KMS is now ready to use the secret key generated on the Securosys HSM in AWS.