Wrap your customer-supplied key
Wrap your symmetric data encryption key with an ephemeral public wrapping key before you can upload it to your instance.
Before you begin
Role required: KMF Admin or KMF Cryptographic Operator
.bin to use these steps. For instructions on this process, see Configure Customer-supplied keys for Field Encryption Enterprise.Token failed validation. Please reattach the unmodified token.
About this task
To modify optional properties that control the size, padding algorithm, and validity period of the key, see Configure properties for customer-supplied key.
You must have a cryptographic tool to wrap your key. The example in this document uses OpenSSL 1.1. For more information on OpenSSL, see details at https://www.openssl.org. If you’re using other cryptographic tools, such as LibreSSL or GnuTLS, refer to the documentation for those products for similar steps.
Procedure
What to do next
Now that your key is wrapped, you can upload it to your instance using the procedure in Upload your customer-supplied key.