← Back to plugin index

AWS Key Management Service

Description
Configures account and key details to use with the Amazon Web Services (AWS) Key Management Service (KMS).

AWS KMS provides a web interface to generate and manage cryptographic keys and acts as a cryptographic service provider.

Airlock IAM utilizes AWS KMS to store encrypted data in its database without having access to the cryptographic key material. AWS KMS can also be used for end-to-end encryption.

Type name
AwsKms
Class
com.airlock.iam.keymanagementservice.application.configuration.AwsKmsConfig
May be used by
License-Tags
AWSKMS
Properties
Service Access (serviceAccessSettings)
Description
Specifies how IAM can access AWS services.

If IAM is deployed in an AWS cluster, it is recommended to use "AWS Default Service Access".

If you want to manually configure AWS access (region/service endpoint), use "AWS Custom Service Access" instead.

Attributes
Plugin-Link
Optional
Assignable plugins
Authentication Method (authenticationSettings)
Description
Specifies how IAM authenticates against AWS services.

If IAM is deployed in an AWS cluster, it is recommended to use "AWS Default Authentication".

If you want to manually configure AWS authentication (access key ID and secret), use "AWS Access Key Authentication" instead.

Attributes
Plugin-Link
Optional
Assignable plugins
Symmetric Key ARN (symmetricKeyArn)
Description
The symmetric KMS key. A symmetric key is used to encrypt/decrypt data on the IAM database, e.g. password hashes.

This key is created in AWS and referenced here by its Amazon Resource Name (ARN). Key ARN and alias ARN are supported.

When automatic key rotation is active on AWS KMS, or if you intend to manually rotate keys, you must specify an alias ARN in this property.

Attributes
String
Optional
RSA Asymmetric Key ARN (asymmetricKeyArn)
Description
The asymmetric KMS key. An asymmetric key is only required if end-to-end encryption in the Loginapp is required.

This key is created in AWS and referenced here by its Amazon Resource Name (ARN). Key ARN and alias ARN are supported.

Since the lifetime of the public key is long, it is possible to save one AWS KMS round trip by downloading the public key and configuring it in "RSA Public Key". Make sure "RSA Asymmetric Key ARN" and "RSA Public Key" always point to the same asymmetric key material.

Attributes
String
Optional
RSA Public Key (publicKey)
Description
The RSA public key of the asymmetric KMS key referenced by "RSA Asymmetric Key ARN".

The public key can be downloaded from AWS directly and referenced here. A Base64 encoded key with or without RSA public key wrapping "BEGIN PUBLIC KEY"/"END PUBLIC KEY" is expected. This is an optimization so that the public key is taken from this property instead of requesting it by its "RSA Asymmetric Key ARN" from AWS for every operation.

Attributes
String
Optional
Multi-line-text
RSA Algorithm (rsaAlgorithm)
Description
The RSA encryption algorithm to use for end-to-end encryption.

The algorithm must be compatible with the KMS key referenced by "RSA Asymmetric Key ARN".

Attributes
Enum
Optional
Default value
RSAES_OAEP_SHA_256
YAML Template (with default values)

type: AwsKms
id: AwsKms-xxxxxx
displayName: 
comment: 
properties:
  asymmetricKeyArn:
  authenticationSettings:
  publicKey:
  rsaAlgorithm: RSAES_OAEP_SHA_256
  serviceAccessSettings:
  symmetricKeyArn: