Managing Azure Key Templates
An Azure Key Template is a predefined structure that enables users to repeatedly create similar types of Azure keys. Once created, it can be reused to generate new keys of the same configuration, ensuring consistency and efficiency.
This section describes how to manage Azure key templates in CCKM. Before you begin, ensure that an Azure key vault is added to CCKM. For more information, see Managing Azure Vaults.
Adding Azure Key Templates
To add an Azure key template:
-
Open the Cloud Key Manager application.
-
In the left pane, click Cloud Keys > Azure.
-
Click the Key Templates tab.
-
Click Add Template. The General Info tab of the Add Template wizard appears.
General Info
-
Enter Template Name.
-
(Optional) Enter Description.
-
(Optional) Enable Overwrite Template Attributes on Key Creation.
-
(Optional) Select a Source. The options are CipherTrust (External), CipherTrust (Local), Luna HSM, and Microsoft Azure (Native).
Click the Clear link to clear your selection.
(Optional) If you select CipherTrust (External) as the source, select a Domain from the drop-down list.
(Optional) If you select Luna HSM as the source, select a Partition ID.
-
Click Next. The Configure Key tab appears.
Configure Key
The fields on the Configure Key tab are optional.
-
Select a Vault.
-
Select a Key Type.
-
Select one or more Key Attributes. The supported attributes are:
-
Encrypt, Decrypt, Sign
-
Verify, Wrap Key, Unwrap Key
-
-
Select the Enable Key check box.
-
(Optional) Enter Tags. A tag is a label assigned to the key that consists of a user-defined key and a value.
To add a tag:
-
Specify a tag name.
-
Specify the tag value.
-
CCKM allows the following characters in tag values:
-
Alphanumeric characters
-
Special characters ** ! @ # $ % ) ( { } > < ? + - / \ [ ] ^ & + = | ~ ` , : ; . ' " _ **
-
-
-
Click the + button.
Similarly, you can add more tags. To remove a tag, click the close (X) icon in the tag name.
-
-
Click Next. The Add to Schedule tab appears.
Add to Schedule
The fields on the Add to Schedule tab are optional.
Warning
Ensure the schedule settings are configured correctly to match the key type and size.
-
Select Rotation Schedule.
-
Select the Key Origin from the available options. The key origin can be:
-
CipherTrust (Local).
-
CipherTrust (External): Also select a Domain.
-
Native (Azure).
-
Luna: Also select a Partition.
-
None.
-
-
Select a Key Type.
-
Select a Key Size.
-
Select the Enable New Key check box.
-
Click Next. The Review and Add tab appears.
Review and Add
The Review and Add tab displays the details you configured for the key template, organized into the GENERAL INFO, CONFIGURE KEY, and KEY SCHEDULES sections.
Review all details before adding the template. Some settings cannot be changed after creation.
-
Review the key template details displayed on the screen.
If details are incorrect or you want to make changes, click Edit next to the GENERAL INFO, CONFIGURE KEY, or KEY SCHEDULES sections to update the details. Alternatively, click Back to make changes.
-
Click Create Template.
A "Key template has been created successfully" message appears.
-
Click Close. The Add Template wizard closes.
The new key template appears in the list of Azure key templates.
Viewing Azure Key Templates
Search for Azure key templates by Template Name.
To view an Azure key template:
-
Open the Cloud Key Manager application.
-
In the left pane, click Cloud Keys > Azure.
-
Click the Key Templates tab. The list of available Azure key templates appears. The Azure Key Templates page displays the following details:
Field Description Template Name The unique, user-friendly name of the key template. Overwrite Template Specifies if template attributes can be overwritten when a key is created. The options are Yes and No. Creation Date The date and time when the template was created. Last Modified The date and time when the template was last updated. Description The description for the key template.
Editing Azure Key Templates
To view or edit an Azure key template:
-
Open the Cloud Key Manager application.
-
In the left pane, click Cloud Keys > Azure.
-
Click the Key Templates tab. The list of available Azure key templates appears.
-
Click the overflow icon (
) next to the desired key template and click View/Edit. Alternatively, click the key template name link. The edit view appears, which is divided into the GENERAL INFO, KEY CONFIGURATION, and KEY SCHEDULES sections.
Updating General Info
To update the general information:
-
Expand the GENERAL INFO section.
-
Update the following details as needed:
-
Description
-
Overwrite Template Attributes on Key Creation
-
Source
-
-
Click Update.
Updating Key Configuration
To update the key configuration:
-
Expand the KEY CONFIGURATION section.
-
Update the following details as needed:
-
Vault
-
Key Type
-
Key Size
-
Key Attributes
-
Select the Enable Key check box.
-
(Optional) Enter Tags. A tag is a label assigned to the key that consists of a user-defined key and a value.
To add a tag:
-
Specify a tag name.
-
Specify the tag value.
-
CCKM allows the following characters in tag values:
-
Alphanumeric characters
-
Special characters ** ! @ # $ % ) ( { } > < ? + - / \ [ ] ^ & + = | ~ ` , : ; . ' " _ **
-
-
-
Click the + button.
Similarly, you can add more tags. To remove a tag, click the close (X) icon in the tag name.
-
-
-
Click Update.
Updating Key Schedules
Warning
Ensure the schedule settings are configured correctly to match the key type and size.
To update the key schedules:
-
Expand the KEY SCHEDULES section.
-
Update the following details as needed:
-
Rotation Schedule
-
Key Origin
-
Key Type
-
Key Size
-
Select the Enable New Key check box.
-
-
Click Update.
Deleting Azure Key Templates
To delete an Azure key template:
-
Open the Cloud Key Manager application.
-
In the left pane, click Cloud Keys > Azure.
-
Click the Key Templates tab. The list of available Azure key templates appears.
-
Click the overflow icon (
) next to the desired key template, and then select Delete. The Delete Template dialog box appears. -
Click Delete Template.
When the template is successfully deleted, a confirmation message appears.