Articles → AWS → Key Management Service In AWS Console

Key Management Service In AWS Console






Purpose





Symmetric And Asymmetric Keys





AWS Managed And Customer Managed Keys





AWS Managed Keys Vs AWS Owned Keys




  1. AWS controls the lifecycle and key policies of AWS managed keys
  2. AWS managed keys are resources in customer AWS accounts
  3. Customers can view CloudTrail events and can access policies and for AWS managed keys
  4. All requests that are made against these keys are logged as CloudTrail events




  1. Keys are exclusively used by AWS for internal encryption operations across different AWS services
  2. Customers do not have visibility into key policies of the AWS owned keys
  3. Requests to these keys are not logged in the CloudTrail events

Difference Between Different Key Types


Type Of CMKCan ViewCan ManageUsed Only For My AWS AccountAutomatic Rotation
Customer Managed CMKYesYesYesOptional. Every 365 days
AWS Managed CMKYesNoYesRequired. Every 1095 days
AWS Owned CMKNoNoNoVaries

How To Create A Key?




Picture showing the Key Management Service in the search box
Click to Enlarge



Picture showing the types of key management service that AWS supports
Click to Enlarge



Picture showing the create a key button for creating the new key in AWS
Click to Enlarge



Picture showing the section of screen for selecting the key type
Click to Enlarge



Picture showing a screen for adding the key name and other details
Click to Enlarge



Picture showing a screen to select the administrative permissions
Click to Enlarge



Picture showing a screen to select the usage permissions
Click to Enlarge



Picture showing a review screen before the creation of key
Click to Enlarge




Posted By  -  Karan Gupta
 
Posted On  -  Tuesday, September 21, 2021
 
Updated On  -  Wednesday, November 9, 2022

Query/Feedback


Your Email Id
 
Subject
 
Query/FeedbackCharacters remaining 250