AWS Key Management Service
AWS KMS provides a web interface to generate and manage cryptographic keys and acts as a cryptographic service provider.
Airlock IAM utilizes AWS KMS to store encrypted data in its database without having access to the cryptographic key material. AWS KMS can also be used for end-to-end encryption.
serviceAccessSettings) If IAM is deployed in an AWS cluster, it is recommended to use "AWS Default Service Access".
If you want to manually configure AWS access (region/service endpoint), use "AWS Custom Service Access" instead.
authenticationSettings) If IAM is deployed in an AWS cluster, it is recommended to use "AWS Default Authentication".
If you want to manually configure AWS authentication (access key ID and secret), use "AWS Access Key Authentication" instead.
symmetricKeyArn) This key is created in AWS and referenced here by its Amazon Resource Name (ARN). Key ARN and alias ARN are supported.
When automatic key rotation is active on AWS KMS, or if you intend to manually rotate keys, you must specify an alias ARN in this property.
asymmetricKeyArn) This key is created in AWS and referenced here by its Amazon Resource Name (ARN). Key ARN and alias ARN are supported.
Since the lifetime of the public key is long, it is possible to save one AWS KMS round trip by downloading the public key and configuring it in "RSA Public Key". Make sure "RSA Asymmetric Key ARN" and "RSA Public Key" always point to the same asymmetric key material.
publicKey) The public key can be downloaded from AWS directly and referenced here. A Base64 encoded key with or without RSA public key wrapping "BEGIN PUBLIC KEY"/"END PUBLIC KEY" is expected. This is an optimization so that the public key is taken from this property instead of requesting it by its "RSA Asymmetric Key ARN" from AWS for every operation.
rsaAlgorithm) The algorithm must be compatible with the KMS key referenced by "RSA Asymmetric Key ARN".
type: AwsKms
id: AwsKms-xxxxxx
displayName:
comment:
properties:
asymmetricKeyArn:
authenticationSettings:
publicKey:
rsaAlgorithm: RSAES_OAEP_SHA_256
serviceAccessSettings:
symmetricKeyArn: