{"id":9382,"date":"2021-12-08T00:51:40","date_gmt":"2021-12-08T00:51:40","guid":{"rendered":"https:\/\/blog.cloudthat.com\/?p=9382"},"modified":"2024-06-25T11:06:18","modified_gmt":"2024-06-25T11:06:18","slug":"cloud-trends-2022-aws-kms-multi-region-key","status":"publish","type":"blog","link":"https:\/\/www.cloudthat.com\/resources\/blog\/cloud-trends-2022-aws-kms-multi-region-key","title":{"rendered":"Cloud Trends 2022: AWS KMS Multi-Region key"},"content":{"rendered":"<p><span data-contrast=\"auto\">Recently AWS Introduced a new Feature called AWS KMS Multi-Regions\u00a0Keys that will support replicate keys from One region into another.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\">\u00a0<\/span><span data-contrast=\"auto\">Using Multi-Regions\u00a0we can easily move the encrypted data from one region to another without having to decrypt and re-encrypt with different keys in each Region.<\/span><\/p>\n<p><a href=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-1.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-9392\" src=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-1-300x192.png\" alt=\"\" width=\"566\" height=\"362\" \/><\/a><\/p>\n<h2>Table of Contents<\/h2>\n<h1><a href=\"#Multi-Region Key\">Multi-Region Key<\/a><\/h1>\n<h1><a href=\"#Primary Key\">Primary Key<\/a><\/h1>\n<h1><a href=\"#Replica Key\">Replica Key<\/a><\/h1>\n<h1><a href=\"#Replicate \">Replicate<\/a><\/h1>\n<h1><a href=\"#KMS Multi-Region Key Creation\">KMS Multi-Region Key Creation<\/a><\/h1>\n<h1><a href=\"#Encrypting EBS Snapshots \">Encrypting EBS Snapshots<\/a><\/h1>\n<h1><a href=\"#Changing Replica key to Primary key \">Changing Replica key to Primary key<\/a><\/h1>\n<h1><a href=\"#KMS Key Rotation\">KMS Key Rotation<\/a><\/h1>\n<h1><a href=\"#Conclusion\">Conclusion<\/a><\/h1>\n<h1 id=\"Multi-Region Key\">Multi-Region Key<\/h1>\n<p><span data-contrast=\"auto\">An AWS regional key can be either symmetric or asymmetric, and it can be generated from AWS KMS key material or imported key material. A custom key store cannot create regional keys. In AWS Multi-Region Key, a set of KMS keys have the same key ID and key material (and other properties) in different AWS Regions.\u00a0Therefore, each KMS key is fully functional and equally usable in any AWS Region.\u00a0Furthermore, each related multi-Region key\u00a0can\u00a0decrypt ciphertext encrypted by any related multi-Region key since they all share a key ID and key material.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">To\u00a0migrate existing workloads to\u00a0multi-Region\u00a0scenarios, you must re-encrypt data or create new signatures with new\u00a0multi-Region\u00a0keys. Once you create a key with a multi-Region property set, this property cannot be changed. Multiple sets of related multi-Region keys can exist in the same or different AWS Regions. While related multi-region keys are interoperable, unrelated multi-region keys are not.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\">\u00a0<\/span><\/p>\n<h1 id=\"Primary Key\">Primary Key<\/h1>\n<p><span class=\"TextRun BCX0 SCXW220850086\" lang=\"EN-IN\" xml:lang=\"EN-IN\" data-contrast=\"auto\"><span class=\"NormalTextRun BCX0 SCXW220850086\" data-ccp-parastyle=\"graf\" data-ccp-parastyle-defn=\"{&quot;ObjectId&quot;:&quot;0eb2a0a2-fc67-45e5-a97c-c3333b980674|83&quot;,&quot;ClassId&quot;:1073872969,&quot;Properties&quot;:[134233117,&quot;true&quot;,134233118,&quot;true&quot;,134233614,&quot;true&quot;,201340122,&quot;2&quot;,335559705,&quot;2057&quot;,469769226,&quot;Times New Roman&quot;,469775450,&quot;graf&quot;,469777841,&quot;Times New Roman&quot;,469777842,&quot;Times New Roman&quot;,469777843,&quot;Times New Roman&quot;,469777844,&quot;Times New Roman&quot;,469778129,&quot;graf&quot;,469778324,&quot;Normal&quot;]}\">In AWS, a multi-Region primary key means a set of keys can be replicated within different AWS Regions in the same partition. A multi-Region key has only one primary key. Primary keys are not required to be replicated. You can use them just like any other KMS key and replicate them when necessary. However,\u00a0<\/span><span class=\"NormalTextRun BCX0 SCXW220850086\" data-ccp-parastyle=\"graf\">we\u00a0<\/span><span class=\"NormalTextRun BCX0 SCXW220850086\" data-ccp-parastyle=\"graf\">recommen<\/span><span class=\"NormalTextRun BCX0 SCXW220850086\" data-ccp-parastyle=\"graf\">d<\/span><span class=\"NormalTextRun BCX0 SCXW220850086\" data-ccp-parastyle=\"graf\">\u00a0creat<\/span><span class=\"NormalTextRun BCX0 SCXW220850086\" data-ccp-parastyle=\"graf\">ing<\/span><span class=\"NormalTextRun BCX0 SCXW220850086\" data-ccp-parastyle=\"graf\">\u00a0a multi-Region key since they have different security properties than single-Region keys.<\/span><\/span><span class=\"EOP BCX0 SCXW220850086\" data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\">\u00a0<\/span><\/p>\n<h1 id=\"Replica Key\">Replica Key<\/h1>\n<p><span data-contrast=\"auto\">Multi-Region replica keys have the same key ID and key material as their primary keys and related replica keys but\u00a0are located in\u00a0a different AWS Regions. Unlike the primary key and all related replica keys, a replica key is a fully functional KMS key with its own policy, grants, alias, tags, and other properties. A replica key may be used even if the primary key and all related replica keys are disabled. You can convert a primary key to a replica key and a replica key to a primary key.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Replica Key is different from Primary key as follows,<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\">\u00a0<\/span><\/p>\n<ol>\n<li data-leveltext=\"%1.\" data-font=\"\" data-listid=\"1\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Only Primary Key can be replicated.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\">\u00a0<\/span><\/li>\n<li data-leveltext=\"%1.\" data-font=\"\" data-listid=\"1\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Primary keys are the source of shared properties of their replica keys, such as key IDs and key materials.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\">\u00a0<\/span><\/li>\n<li data-leveltext=\"%1.\" data-font=\"\" data-listid=\"1\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Automatic key rotation can be enabled or disabled only on primary keys.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\">\u00a0<\/span><\/li>\n<li data-leveltext=\"%1.\" data-font=\"\" data-listid=\"1\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">Primary keys can be scheduled for deletion at any time. However, AWS KMS will not delete a primary key until all its replica keys have been deleted.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\">\u00a0<\/span><\/li>\n<\/ol>\n<p><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\">\u00a0<\/span><span data-contrast=\"auto\">Despite this, primary and replica keys\u00a0do not\u00a0differ in any cryptographic properties. They can be used interchangeably.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\">\u00a0<\/span><\/p>\n<h1 id=\"Replicate\">Replicate<\/h1>\n<p><span class=\"TextRun SCXW56162936 BCX0\" lang=\"EN-IN\" xml:lang=\"EN-IN\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW56162936 BCX0\" data-ccp-parastyle=\"graf\" data-ccp-parastyle-defn=\"{&quot;ObjectId&quot;:&quot;0eb2a0a2-fc67-45e5-a97c-c3333b980674|83&quot;,&quot;ClassId&quot;:1073872969,&quot;Properties&quot;:[134233117,&quot;true&quot;,134233118,&quot;true&quot;,134233614,&quot;true&quot;,201340122,&quot;2&quot;,335559705,&quot;2057&quot;,469769226,&quot;Times New Roman&quot;,469775450,&quot;graf&quot;,469777841,&quot;Times New Roman&quot;,469777842,&quot;Times New Roman&quot;,469777843,&quot;Times New Roman&quot;,469777844,&quot;Times New Roman&quot;,469778129,&quot;graf&quot;,469778324,&quot;Normal&quot;]}\">It is possible to\u00a0<\/span><\/span><span class=\"TextRun SCXW56162936 BCX0\" lang=\"EN-IN\" xml:lang=\"EN-IN\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW56162936 BCX0\" data-ccp-charstyle=\"Emphasis\">replicate<\/span><\/span><span class=\"TextRun SCXW56162936 BCX0\" lang=\"EN-IN\" xml:lang=\"EN-IN\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW56162936 BCX0\" data-ccp-parastyle=\"graf\">\u00a0a multi-Region primary key into a different AWS Region in the same partition. When you replicate the primary key into a replica key, AWS KMS creates a multi-Region replica key in the specified Region with the same key ID and other shared properties as its primary key.<\/span><\/span><span class=\"EOP SCXW56162936 BCX0\" data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\">\u00a0<\/span><\/p>\n<h1 id=\"KMS Multi-Region Key Creation\">KMS Multi-Region Key Creation<\/h1>\n<p><span data-contrast=\"auto\">Now we are going to see how AWS KMS Multi-Region work using the following example:<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">1.Go to\u00a0the\u00a0AWS Console, and select KMS from the AWS Service List, then click on Create a Key.<a href=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-2.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-9393\" src=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-2-300x114.png\" alt=\"\" width=\"595\" height=\"226\" \/><\/a><\/span><\/p>\n<p><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\"><span class=\"TextRun SCXW218718001 BCX0\" lang=\"EN-IN\" xml:lang=\"EN-IN\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW218718001 BCX0\" data-ccp-parastyle=\"graf\" data-ccp-parastyle-defn=\"{&quot;ObjectId&quot;:&quot;a4de1dfa-ac58-4fbf-b405-f0ef81cf38d8|83&quot;,&quot;ClassId&quot;:1073872969,&quot;Properties&quot;:[134233117,&quot;true&quot;,134233118,&quot;true&quot;,134233614,&quot;true&quot;,201340122,&quot;2&quot;,335559705,&quot;2057&quot;,469769226,&quot;Times New Roman&quot;,469775450,&quot;graf&quot;,469777841,&quot;Times New Roman&quot;,469777842,&quot;Times New Roman&quot;,469777843,&quot;Times New Roman&quot;,469777844,&quot;Times New Roman&quot;,469778129,&quot;graf&quot;,469778324,&quot;Normal&quot;]}\">2. Select the Symmetric key and click Advanced Options<\/span><span class=\"NormalTextRun SCXW218718001 BCX0\" data-ccp-parastyle=\"graf\">.\u00a0\u00a0<\/span><\/span><\/span><\/p>\n<p><a href=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-3.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-9396\" src=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-3-300x124.png\" alt=\"\" width=\"585\" height=\"242\" \/><\/a><\/p>\n<p><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\"><span class=\"EOP SCXW218718001 BCX0\" data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\"><span class=\"TextRun SCXW205033921 BCX0\" lang=\"EN-IN\" xml:lang=\"EN-IN\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW205033921 BCX0\" data-ccp-parastyle=\"graf\" data-ccp-parastyle-defn=\"{&quot;ObjectId&quot;:&quot;a4de1dfa-ac58-4fbf-b405-f0ef81cf38d8|83&quot;,&quot;ClassId&quot;:1073872969,&quot;Properties&quot;:[134233117,&quot;true&quot;,134233118,&quot;true&quot;,134233614,&quot;true&quot;,201340122,&quot;2&quot;,335559705,&quot;2057&quot;,469769226,&quot;Times New Roman&quot;,469775450,&quot;graf&quot;,469777841,&quot;Times New Roman&quot;,469777842,&quot;Times New Roman&quot;,469777843,&quot;Times New Roman&quot;,469777844,&quot;Times New Roman&quot;,469778129,&quot;graf&quot;,469778324,&quot;Normal&quot;]}\">3. Select KMS and Mult-Region-Key from the list and click on Next<\/span><span class=\"NormalTextRun SCXW205033921 BCX0\" data-ccp-parastyle=\"graf\">.<\/span><\/span><span class=\"EOP SCXW205033921 BCX0\" data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\">\u00a0<\/span><\/span><\/span><\/p>\n<p><a href=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-4.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-9397\" src=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-4-300x121.png\" alt=\"\" width=\"580\" height=\"234\" \/><\/a><\/p>\n<p><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\"><span class=\"EOP SCXW218718001 BCX0\" data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\"><span class=\"TextRun SCXW126983974 BCX0\" lang=\"EN-IN\" xml:lang=\"EN-IN\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW126983974 BCX0\" data-ccp-parastyle=\"graf\" data-ccp-parastyle-defn=\"{&quot;ObjectId&quot;:&quot;a4de1dfa-ac58-4fbf-b405-f0ef81cf38d8|83&quot;,&quot;ClassId&quot;:1073872969,&quot;Properties&quot;:[134233117,&quot;true&quot;,134233118,&quot;true&quot;,134233614,&quot;true&quot;,201340122,&quot;2&quot;,335559705,&quot;2057&quot;,469769226,&quot;Times New Roman&quot;,469775450,&quot;graf&quot;,469777841,&quot;Times New Roman&quot;,469777842,&quot;Times New Roman&quot;,469777843,&quot;Times New Roman&quot;,469777844,&quot;Times New Roman&quot;,469778129,&quot;graf&quot;,469778324,&quot;Normal&quot;]}\">4. Provide the Alias Name and Description in the respective field<\/span><span class=\"NormalTextRun SCXW126983974 BCX0\" data-ccp-parastyle=\"graf\">.<\/span><\/span><span class=\"EOP SCXW126983974 BCX0\" data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\">\u00a0<\/span><\/span><\/span><\/p>\n<p><a href=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-5.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-9398\" src=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-5-300x154.png\" alt=\"\" width=\"575\" height=\"295\" \/><\/a><\/p>\n<p><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\"><span class=\"EOP SCXW218718001 BCX0\" data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\"><span class=\"TextRun SCXW128061409 BCX0\" lang=\"EN-IN\" xml:lang=\"EN-IN\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW128061409 BCX0\" data-ccp-parastyle=\"graf\" data-ccp-parastyle-defn=\"{&quot;ObjectId&quot;:&quot;a4de1dfa-ac58-4fbf-b405-f0ef81cf38d8|83&quot;,&quot;ClassId&quot;:1073872969,&quot;Properties&quot;:[134233117,&quot;true&quot;,134233118,&quot;true&quot;,134233614,&quot;true&quot;,201340122,&quot;2&quot;,335559705,&quot;2057&quot;,469769226,&quot;Times New Roman&quot;,469775450,&quot;graf&quot;,469777841,&quot;Times New Roman&quot;,469777842,&quot;Times New Roman&quot;,469777843,&quot;Times New Roman&quot;,469777844,&quot;Times New Roman&quot;,469778129,&quot;graf&quot;,469778324,&quot;Normal&quot;]}\">5. Give Appropriate Tags and click on Next<\/span><\/span><span class=\"EOP SCXW128061409 BCX0\" data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\">\u00a0<\/span><\/span><\/span><\/p>\n<p><a href=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-6.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-9399\" src=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-6-300x93.png\" alt=\"\" width=\"574\" height=\"178\" \/><\/a><\/p>\n<p><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\"><span class=\"EOP SCXW218718001 BCX0\" data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\"><span class=\"TextRun SCXW182551474 BCX0\" lang=\"EN-IN\" xml:lang=\"EN-IN\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW182551474 BCX0\" data-ccp-parastyle=\"graf\" data-ccp-parastyle-defn=\"{&quot;ObjectId&quot;:&quot;a4de1dfa-ac58-4fbf-b405-f0ef81cf38d8|83&quot;,&quot;ClassId&quot;:1073872969,&quot;Properties&quot;:[134233117,&quot;true&quot;,134233118,&quot;true&quot;,134233614,&quot;true&quot;,201340122,&quot;2&quot;,335559705,&quot;2057&quot;,469769226,&quot;Times New Roman&quot;,469775450,&quot;graf&quot;,469777841,&quot;Times New Roman&quot;,469777842,&quot;Times New Roman&quot;,469777843,&quot;Times New Roman&quot;,469777844,&quot;Times New Roman&quot;,469778129,&quot;graf&quot;,469778324,&quot;Normal&quot;]}\">6. Now you need to provide the\u00a0<\/span><span class=\"NormalTextRun SCXW182551474 BCX0\" data-ccp-parastyle=\"graf\">IAM (Identity and Access Management)<\/span><span class=\"NormalTextRun SCXW182551474 BCX0\" data-ccp-parastyle=\"graf\">\u00a0users and roles who can administer this key through the KMS API. You may need to add additional permissions for the users or roles to administer this key from this console.<\/span><\/span><span class=\"EOP SCXW182551474 BCX0\" data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\">\u00a0<\/span><\/span><\/span><\/p>\n<p><a href=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-7.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-9400\" src=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-7-300x173.png\" alt=\"\" width=\"560\" height=\"323\" \/><\/a><\/p>\n<p><span data-contrast=\"auto\">7.\u00a0 You can select the\u00a0<\/span><i><span data-contrast=\"auto\">Allow key administrators to delete this key\u00a0<\/span><\/i><span data-contrast=\"auto\">option if you want to allow your Administrators to delete the key which you are creating and click on Next.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\">\u00a0<\/span><\/p>\n<p><a href=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-8.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-9401\" src=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-8-300x70.png\" alt=\"\" width=\"558\" height=\"130\" \/><\/a><\/p>\n<p><span class=\"NormalTextRun SCXW215935531 BCX0\" data-ccp-parastyle=\"graf\" data-ccp-parastyle-defn=\"{&quot;ObjectId&quot;:&quot;a4de1dfa-ac58-4fbf-b405-f0ef81cf38d8|83&quot;,&quot;ClassId&quot;:1073872969,&quot;Properties&quot;:[134233117,&quot;true&quot;,134233118,&quot;true&quot;,134233614,&quot;true&quot;,201340122,&quot;2&quot;,335559705,&quot;2057&quot;,469769226,&quot;Times New Roman&quot;,469775450,&quot;graf&quot;,469777841,&quot;Times New Roman&quot;,469777842,&quot;Times New Roman&quot;,469777843,&quot;Times New Roman&quot;,469777844,&quot;Times New Roman&quot;,469778129,&quot;graf&quot;,469778324,&quot;Normal&quot;]}\">8. Now you can Define the key usage permissions. By choosing this option you can select the IAM users and roles that can use the KMS key in cryptographic operations.<\/span><span class=\"EOP SCXW215935531 BCX0\" data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\">\u00a0<\/span><\/p>\n<p><a href=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-9.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-9402\" src=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-9-300x165.png\" alt=\"\" width=\"555\" height=\"305\" \/><\/a><\/p>\n<p><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\"><span class=\"TextRun SCXW205845217 BCX0\" lang=\"EN-IN\" xml:lang=\"EN-IN\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW205845217 BCX0\" data-ccp-parastyle=\"graf\" data-ccp-parastyle-defn=\"{&quot;ObjectId&quot;:&quot;a4de1dfa-ac58-4fbf-b405-f0ef81cf38d8|83&quot;,&quot;ClassId&quot;:1073872969,&quot;Properties&quot;:[134233117,&quot;true&quot;,134233118,&quot;true&quot;,134233614,&quot;true&quot;,201340122,&quot;2&quot;,335559705,&quot;2057&quot;,469769226,&quot;Times New Roman&quot;,469775450,&quot;graf&quot;,469777841,&quot;Times New Roman&quot;,469777842,&quot;Times New Roman&quot;,469777843,&quot;Times New Roman&quot;,469777844,&quot;Times New Roman&quot;,469778129,&quot;graf&quot;,469778324,&quot;Normal&quot;]}\">9. If you want to specify this key with other AWS Accounts, you can add the AWS Account ID in the below section, (I am not using this option in this Demo.)<\/span><\/span><span class=\"EOP SCXW205845217 BCX0\" data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\">\u00a0<\/span><\/span><\/p>\n<p><a href=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-10.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-9404\" src=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-10-300x115.png\" alt=\"\" width=\"553\" height=\"212\" \/><\/a><\/p>\n<p>10. Now you can Review the KMS Configurations and the key policy.<\/p>\n<p><a href=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-11.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-9405\" src=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-11-300x143.png\" alt=\"\" width=\"544\" height=\"259\" \/><\/a><\/p>\n<p><a href=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-12.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-9406\" src=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-12-300x153.png\" alt=\"\" width=\"545\" height=\"278\" \/><\/a><\/p>\n<p><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\"><span class=\"TextRun BCX0 SCXW186803510\" lang=\"EN-IN\" xml:lang=\"EN-IN\" data-contrast=\"auto\"><span class=\"NormalTextRun BCX0 SCXW186803510\" data-ccp-parastyle=\"graf\" data-ccp-parastyle-defn=\"{&quot;ObjectId&quot;:&quot;a4de1dfa-ac58-4fbf-b405-f0ef81cf38d8|83&quot;,&quot;ClassId&quot;:1073872969,&quot;Properties&quot;:[134233117,&quot;true&quot;,134233118,&quot;true&quot;,134233614,&quot;true&quot;,201340122,&quot;2&quot;,335559705,&quot;2057&quot;,469769226,&quot;Times New Roman&quot;,469775450,&quot;graf&quot;,469777841,&quot;Times New Roman&quot;,469777842,&quot;Times New Roman&quot;,469777843,&quot;Times New Roman&quot;,469777844,&quot;Times New Roman&quot;,469778129,&quot;graf&quot;,469778324,&quot;Normal&quot;]}\">11. After clicking on Finish, you can see your KMS Key in the KMS key console<\/span><\/span>\u00a0<\/span><\/p>\n<p><a href=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-131.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-9409\" src=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-131-300x145.png\" alt=\"\" width=\"553\" height=\"267\" \/><\/a><\/p>\n<p><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\"><span class=\"EOP SCXW218718001 BCX0\" data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\">\u00a0<\/span>\u00a0<\/span><\/p>\n<h1 id=\"Encrypting EBS Snapshots\">Encrypting EBS Snapshots<\/h1>\n<p><span data-contrast=\"auto\">Now I am going to copy an AMI from the Mumbai region to Tokyo region after encrypting the EBS Snapshots by using the key which we created earlier.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\">\u00a0<\/span><\/p>\n<p><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\">1.\u00a0<\/span><span data-contrast=\"auto\">Go to the EC2 Console and select the AMIs section Under Images. Now select the AMI which you want to encrypt.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\">\u00a0<\/span><\/p>\n<p><a href=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-14.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-9410\" src=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-14-300x86.png\" alt=\"\" width=\"552\" height=\"158\" \/><\/a><\/p>\n<p><span class=\"NormalTextRun SCXW6826722 BCX0\" data-ccp-parastyle=\"graf\" data-ccp-parastyle-defn=\"{&quot;ObjectId&quot;:&quot;a4de1dfa-ac58-4fbf-b405-f0ef81cf38d8|83&quot;,&quot;ClassId&quot;:1073872969,&quot;Properties&quot;:[134233117,&quot;true&quot;,134233118,&quot;true&quot;,134233614,&quot;true&quot;,201340122,&quot;2&quot;,335559705,&quot;2057&quot;,469769226,&quot;Times New Roman&quot;,469775450,&quot;graf&quot;,469777841,&quot;Times New Roman&quot;,469777842,&quot;Times New Roman&quot;,469777843,&quot;Times New Roman&quot;,469777844,&quot;Times New Roman&quot;,469778129,&quot;graf&quot;,469778324,&quot;Normal&quot;]}\">2. Now click on Actions and select the Copy AMI option<\/span><span class=\"NormalTextRun SCXW6826722 BCX0\" data-ccp-parastyle=\"graf\">.<\/span><\/p>\n<p><a href=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-15.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-9411\" src=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-15-300x97.png\" alt=\"\" width=\"548\" height=\"177\" \/><\/a><\/p>\n<p><span class=\"TextRun SCXW126647366 BCX0\" lang=\"EN-IN\" xml:lang=\"EN-IN\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW126647366 BCX0\" data-ccp-parastyle=\"graf\" data-ccp-parastyle-defn=\"{&quot;ObjectId&quot;:&quot;a4de1dfa-ac58-4fbf-b405-f0ef81cf38d8|83&quot;,&quot;ClassId&quot;:1073872969,&quot;Properties&quot;:[134233117,&quot;true&quot;,134233118,&quot;true&quot;,134233614,&quot;true&quot;,201340122,&quot;2&quot;,335559705,&quot;2057&quot;,469769226,&quot;Times New Roman&quot;,469775450,&quot;graf&quot;,469777841,&quot;Times New Roman&quot;,469777842,&quot;Times New Roman&quot;,469777843,&quot;Times New Roman&quot;,469777844,&quot;Times New Roman&quot;,469778129,&quot;graf&quot;,469778324,&quot;Normal&quot;]}\">3.\u00a0 I have Selected Destination Region as\u00a0<\/span><\/span><span class=\"TextRun SCXW126647366 BCX0\" lang=\"EN-IN\" xml:lang=\"EN-IN\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW126647366 BCX0\" data-ccp-charstyle=\"Emphasis\">Tokyo\u00a0<\/span><\/span><span class=\"TextRun SCXW126647366 BCX0\" lang=\"EN-IN\" xml:lang=\"EN-IN\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW126647366 BCX0\" data-ccp-parastyle=\"graf\">and select the<\/span><\/span><span class=\"TextRun SCXW126647366 BCX0\" lang=\"EN-IN\" xml:lang=\"EN-IN\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW126647366 BCX0\" data-ccp-charstyle=\"Emphasis\">\u00a0Encrypt target EBS snapshots<\/span><\/span><span class=\"TextRun SCXW126647366 BCX0\" lang=\"EN-IN\" xml:lang=\"EN-IN\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW126647366 BCX0\" data-ccp-parastyle=\"graf\">\u00a0option.\u00a0<\/span><\/span><span data-contrast=\"auto\">But I am not able to see the Key which we created earlier. For that, we need to Replicate our Primary Key from Mumbai to Tokyo Region.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\">\u00a0<\/span><\/p>\n<p><a href=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-16.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-9412\" src=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-16-300x169.png\" alt=\"\" width=\"548\" height=\"309\" \/><\/a><\/p>\n<p>4. Go back to the KMS Console and select the key which we created earlier, then select the Regionality option.<\/p>\n<p><a href=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-17.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-9413\" src=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-17-300x158.png\" alt=\"\" width=\"546\" height=\"287\" \/><\/a><\/p>\n<p><span class=\"TextRun SCXW120020631 BCX0\" lang=\"EN-IN\" xml:lang=\"EN-IN\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW120020631 BCX0\" data-ccp-parastyle=\"graf\" data-ccp-parastyle-defn=\"{&quot;ObjectId&quot;:&quot;a4de1dfa-ac58-4fbf-b405-f0ef81cf38d8|83&quot;,&quot;ClassId&quot;:1073872969,&quot;Properties&quot;:[134233117,&quot;true&quot;,134233118,&quot;true&quot;,134233614,&quot;true&quot;,201340122,&quot;2&quot;,335559705,&quot;2057&quot;,469769226,&quot;Times New Roman&quot;,469775450,&quot;graf&quot;,469777841,&quot;Times New Roman&quot;,469777842,&quot;Times New Roman&quot;,469777843,&quot;Times New Roman&quot;,469777844,&quot;Times New Roman&quot;,469778129,&quot;graf&quot;,469778324,&quot;Normal&quot;]}\">5. Now select the\u00a0<\/span><\/span><span class=\"TextRun SCXW120020631 BCX0\" lang=\"EN-IN\" xml:lang=\"EN-IN\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW120020631 BCX0\" data-ccp-charstyle=\"Emphasis\">Create new replica keys\u00a0<\/span><\/span><span class=\"TextRun SCXW120020631 BCX0\" lang=\"EN-IN\" xml:lang=\"EN-IN\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW120020631 BCX0\" data-ccp-parastyle=\"graf\">option,<\/span><\/span><\/p>\n<p><a href=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-18.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-9415\" src=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-18-300x76.png\" alt=\"\" width=\"552\" height=\"140\" \/><\/a><\/p>\n<p><span class=\"TextRun SCXW36460162 BCX0\" lang=\"EN-IN\" xml:lang=\"EN-IN\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW36460162 BCX0\" data-ccp-parastyle=\"graf\" data-ccp-parastyle-defn=\"{&quot;ObjectId&quot;:&quot;a4de1dfa-ac58-4fbf-b405-f0ef81cf38d8|83&quot;,&quot;ClassId&quot;:1073872969,&quot;Properties&quot;:[134233117,&quot;true&quot;,134233118,&quot;true&quot;,134233614,&quot;true&quot;,201340122,&quot;2&quot;,335559705,&quot;2057&quot;,469769226,&quot;Times New Roman&quot;,469775450,&quot;graf&quot;,469777841,&quot;Times New Roman&quot;,469777842,&quot;Times New Roman&quot;,469777843,&quot;Times New Roman&quot;,469777844,&quot;Times New Roman&quot;,469778129,&quot;graf&quot;,469778324,&quot;Normal&quot;]}\">6.\u00a0 Now select the Replica Region as Tokyo and click on Next<\/span><span class=\"NormalTextRun SCXW36460162 BCX0\" data-ccp-parastyle=\"graf\">.<\/span><\/span><span class=\"EOP SCXW36460162 BCX0\" data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\">\u00a0<\/span><\/p>\n<p><a href=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-19.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-9416\" src=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-19-300x123.png\" alt=\"\" width=\"549\" height=\"225\" \/><\/a><\/p>\n<p><span class=\"TextRun BCX0 SCXW129104636\" lang=\"EN-IN\" xml:lang=\"EN-IN\" data-contrast=\"auto\"><span class=\"NormalTextRun BCX0 SCXW129104636\" data-ccp-parastyle=\"graf\" data-ccp-parastyle-defn=\"{&quot;ObjectId&quot;:&quot;a4de1dfa-ac58-4fbf-b405-f0ef81cf38d8|83&quot;,&quot;ClassId&quot;:1073872969,&quot;Properties&quot;:[134233117,&quot;true&quot;,134233118,&quot;true&quot;,134233614,&quot;true&quot;,201340122,&quot;2&quot;,335559705,&quot;2057&quot;,469769226,&quot;Times New Roman&quot;,469775450,&quot;graf&quot;,469777841,&quot;Times New Roman&quot;,469777842,&quot;Times New Roman&quot;,469777843,&quot;Times New Roman&quot;,469777844,&quot;Times New Roman&quot;,469778129,&quot;graf&quot;,469778324,&quot;Normal&quot;]}\">7. Now you can see the current values of the primary key. But you can change them. AWS KMS does\u00a0<\/span><\/span><span class=\"TextRun BCX0 SCXW129104636\" lang=\"EN-IN\" xml:lang=\"EN-IN\" data-contrast=\"auto\"><span class=\"NormalTextRun BCX0 SCXW129104636\" data-ccp-charstyle=\"Emphasis\">not<\/span><\/span><span class=\"TextRun BCX0 SCXW129104636\" lang=\"EN-IN\" xml:lang=\"EN-IN\" data-contrast=\"auto\"><span class=\"NormalTextRun BCX0 SCXW129104636\" data-ccp-parastyle=\"graf\">\u00a0synchronize any changes to these values.\u00a0<\/span><span class=\"NormalTextRun BCX0 SCXW129104636\" data-ccp-parastyle=\"graf\">C<\/span><span class=\"NormalTextRun BCX0 SCXW129104636\" data-ccp-parastyle=\"graf\">lick on Next<\/span><span class=\"NormalTextRun BCX0 SCXW129104636\" data-ccp-parastyle=\"graf\">.<\/span><\/span><\/p>\n<p><a href=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-20.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-9417\" src=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-20-300x174.png\" alt=\"\" width=\"556\" height=\"322\" \/><\/a><\/p>\n<p><span class=\"TextRun SCXW223212565 BCX0\" lang=\"EN-IN\" xml:lang=\"EN-IN\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW223212565 BCX0\" data-ccp-parastyle=\"graf\" data-ccp-parastyle-defn=\"{&quot;ObjectId&quot;:&quot;a4de1dfa-ac58-4fbf-b405-f0ef81cf38d8|83&quot;,&quot;ClassId&quot;:1073872969,&quot;Properties&quot;:[134233117,&quot;true&quot;,134233118,&quot;true&quot;,134233614,&quot;true&quot;,201340122,&quot;2&quot;,335559705,&quot;2057&quot;,469769226,&quot;Times New Roman&quot;,469775450,&quot;graf&quot;,469777841,&quot;Times New Roman&quot;,469777842,&quot;Times New Roman&quot;,469777843,&quot;Times New Roman&quot;,469777844,&quot;Times New Roman&quot;,469778129,&quot;graf&quot;,469778324,&quot;Normal&quot;]}\">8. In the next field, we can see the current values of the primary key, but you can change them. AWS KMS does\u00a0<\/span><\/span><span class=\"TextRun SCXW223212565 BCX0\" lang=\"EN-IN\" xml:lang=\"EN-IN\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW223212565 BCX0\" data-ccp-charstyle=\"Emphasis\">not<\/span><\/span><span class=\"TextRun SCXW223212565 BCX0\" lang=\"EN-IN\" xml:lang=\"EN-IN\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW223212565 BCX0\" data-ccp-parastyle=\"graf\">\u00a0synchronize any changes to these values.<\/span><\/span><\/p>\n<p><a href=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-211.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-9419\" src=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-211-300x207.png\" alt=\"\" width=\"545\" height=\"376\" \/><\/a><\/p>\n<p><span class=\"TextRun SCXW18268349 BCX0\" lang=\"EN-IN\" xml:lang=\"EN-IN\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW18268349 BCX0\">9 . This field displays the current values of the primary key, but you can change them. AWS KMS does\u00a0<\/span><\/span><span class=\"TextRun SCXW18268349 BCX0\" lang=\"EN-IN\" xml:lang=\"EN-IN\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW18268349 BCX0\" data-ccp-charstyle=\"Emphasis\">not<\/span><\/span><span class=\"TextRun SCXW18268349 BCX0\" lang=\"EN-IN\" xml:lang=\"EN-IN\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW18268349 BCX0\">\u00a0synchronize any changes to these values.<\/span><\/span><span class=\"EOP SCXW18268349 BCX0\" data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<p><a href=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-22.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-9420\" src=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-22-300x173.png\" alt=\"\" width=\"540\" height=\"311\" \/><\/a><\/p>\n<p><span class=\"NormalTextRun SCXW222250535 BCX0\" data-ccp-parastyle=\"graf\" data-ccp-parastyle-defn=\"{&quot;ObjectId&quot;:&quot;a4de1dfa-ac58-4fbf-b405-f0ef81cf38d8|83&quot;,&quot;ClassId&quot;:1073872969,&quot;Properties&quot;:[134233117,&quot;true&quot;,134233118,&quot;true&quot;,134233614,&quot;true&quot;,201340122,&quot;2&quot;,335559705,&quot;2057&quot;,469769226,&quot;Times New Roman&quot;,469775450,&quot;graf&quot;,469777841,&quot;Times New Roman&quot;,469777842,&quot;Times New Roman&quot;,469777843,&quot;Times New Roman&quot;,469777844,&quot;Times New Roman&quot;,469778129,&quot;graf&quot;,469778324,&quot;Normal&quot;]}\">10. Review the Key Configurations, Policy and Click on Create new replica keys<\/span><span class=\"NormalTextRun SCXW222250535 BCX0\" data-ccp-parastyle=\"graf\">.<\/span><\/p>\n<p><a href=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-23.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-9421\" src=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-23-300x191.png\" alt=\"\" width=\"546\" height=\"348\" \/><\/a><\/p>\n<p><span class=\"TextRun SCXW166490983 BCX0\" lang=\"EN-IN\" xml:lang=\"EN-IN\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW166490983 BCX0\" data-ccp-parastyle=\"graf\" data-ccp-parastyle-defn=\"{&quot;ObjectId&quot;:&quot;a4de1dfa-ac58-4fbf-b405-f0ef81cf38d8|83&quot;,&quot;ClassId&quot;:1073872969,&quot;Properties&quot;:[134233117,&quot;true&quot;,134233118,&quot;true&quot;,134233614,&quot;true&quot;,201340122,&quot;2&quot;,335559705,&quot;2057&quot;,469769226,&quot;Times New Roman&quot;,469775450,&quot;graf&quot;,469777841,&quot;Times New Roman&quot;,469777842,&quot;Times New Roman&quot;,469777843,&quot;Times New Roman&quot;,469777844,&quot;Times New Roman&quot;,469778129,&quot;graf&quot;,469778324,&quot;Normal&quot;]}\">11. Now we can see the Replica key in the Tokyo region.<\/span><\/span><\/p>\n<p><span class=\"EOP SCXW166490983 BCX0\" data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\"><a href=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-24.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-9422\" src=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/KMS-KEY-Blog-Pic-24-300x69.png\" alt=\"\" width=\"547\" height=\"126\" \/><\/a>\u00a0<\/span><\/p>\n<p><span class=\"TextRun SCXW262076734 BCX0\" lang=\"EN-IN\" xml:lang=\"EN-IN\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW262076734 BCX0\" data-ccp-parastyle=\"graf\" data-ccp-parastyle-defn=\"{&quot;ObjectId&quot;:&quot;a4de1dfa-ac58-4fbf-b405-f0ef81cf38d8|83&quot;,&quot;ClassId&quot;:1073872969,&quot;Properties&quot;:[134233117,&quot;true&quot;,134233118,&quot;true&quot;,134233614,&quot;true&quot;,201340122,&quot;2&quot;,335559705,&quot;2057&quot;,469769226,&quot;Times New Roman&quot;,469775450,&quot;graf&quot;,469777841,&quot;Times New Roman&quot;,469777842,&quot;Times New Roman&quot;,469777843,&quot;Times New Roman&quot;,469777844,&quot;Times New Roman&quot;,469778129,&quot;graf&quot;,469778324,&quot;Normal&quot;]}\">12.\u00a0 Now we can go back to the EC2 Dashboard and copy the AMI to the Tokyo region, now we can see our key in the list. Select the key and click on Copy AMI<\/span><span class=\"NormalTextRun SCXW262076734 BCX0\" data-ccp-parastyle=\"graf\">.<\/span><\/span><span class=\"EOP SCXW262076734 BCX0\" data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\">\u00a0<\/span><\/p>\n<p><a href=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/Picture120.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-9428\" src=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/Picture120-300x215.png\" alt=\"\" width=\"550\" height=\"394\" \/><\/a><\/p>\n<p><span data-contrast=\"auto\">13. After Completing the sharing, you can see the Encrypted EBS Snapshots.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\">\u00a0<\/span><span class=\"EOP SCXW59353695 BCX0\" data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\">\u00a0<\/span><\/p>\n<p><a href=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/Picture28.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-9429\" src=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/Picture28-300x162.png\" alt=\"\" width=\"549\" height=\"296\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<h1 id=\"Changing Replica key to Primary key\">Changing Replica key to Primary key<\/h1>\n<ol>\n<li><span data-contrast=\"auto\">We can also change any replica to the primary key. For that, we need to go to the region in which we have the Primary Key,\u00a0then\u00a0select the key and choose the Regionality option and click on Change primary Region.<\/span><\/li>\n<\/ol>\n<p><span data-contrast=\"auto\"><a href=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/Picture35.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-9430\" src=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/Picture35-300x112.png\" alt=\"\" width=\"555\" height=\"207\" \/><\/a><\/span><\/p>\n<p><span class=\"TextRun SCXW260370101 BCX0\" lang=\"EN-IN\" xml:lang=\"EN-IN\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW260370101 BCX0\" data-ccp-parastyle=\"graf\" data-ccp-parastyle-defn=\"{&quot;ObjectId&quot;:&quot;a4de1dfa-ac58-4fbf-b405-f0ef81cf38d8|83&quot;,&quot;ClassId&quot;:1073872969,&quot;Properties&quot;:[134233117,&quot;true&quot;,134233118,&quot;true&quot;,134233614,&quot;true&quot;,201340122,&quot;2&quot;,335559705,&quot;2057&quot;,469769226,&quot;Times New Roman&quot;,469775450,&quot;graf&quot;,469777841,&quot;Times New Roman&quot;,469777842,&quot;Times New Roman&quot;,469777843,&quot;Times New Roman&quot;,469777844,&quot;Times New Roman&quot;,469778129,&quot;graf&quot;,469778324,&quot;Normal&quot;]}\">2 . Select the Region from the dropdown menu and click on Change primary Region<\/span><span class=\"NormalTextRun SCXW260370101 BCX0\" data-ccp-parastyle=\"graf\">.<\/span><\/span><span class=\"EOP SCXW260370101 BCX0\" data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\">\u00a0<\/span><\/p>\n<p><a href=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/Picture45.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-9431\" src=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/Picture45-300x122.png\" alt=\"\" width=\"554\" height=\"225\" \/><\/a><\/p>\n<p>3. Now you can see the Primary key is converted to the Replica key and the Replica key is converted to the Primary key.<\/p>\n<p><a href=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/Picture52.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-9432\" src=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/Picture52-300x105.png\" alt=\"\" width=\"549\" height=\"192\" \/><\/a><\/p>\n<p><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\">\u00a0<\/span><\/p>\n<h1 id=\"KMS Key Rotation\">KMS Key Rotation<\/h1>\n<p><span class=\"TextRun SCXW101656258 BCX0\" lang=\"EN-IN\" xml:lang=\"EN-IN\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW101656258 BCX0\" data-ccp-parastyle=\"graf\" data-ccp-parastyle-defn=\"{&quot;ObjectId&quot;:&quot;a4de1dfa-ac58-4fbf-b405-f0ef81cf38d8|83&quot;,&quot;ClassId&quot;:1073872969,&quot;Properties&quot;:[134233117,&quot;true&quot;,134233118,&quot;true&quot;,134233614,&quot;true&quot;,201340122,&quot;2&quot;,335559705,&quot;2057&quot;,469769226,&quot;Times New Roman&quot;,469775450,&quot;graf&quot;,469777841,&quot;Times New Roman&quot;,469777842,&quot;Times New Roman&quot;,469777843,&quot;Times New Roman&quot;,469777844,&quot;Times New Roman&quot;,469778129,&quot;graf&quot;,469778324,&quot;Normal&quot;]}\">\u00a0<\/span><\/span><\/p>\n<p><span data-contrast=\"auto\">As a best practice,\u00a0you\u00a0can create new KMS keys and then change your applications to use the new ones. You can also enable automatic key rotation for existing KMS keys.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">AWS KMS can generate new cryptographic material for a KMS key every year when you enable automatic key rotation, and it can also keep the key\u2019s older cryptographic material in perpetuity so it can be used to decrypt the data that the key encrypted.<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\">\u00a0<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\">\u00a0<\/span><\/p>\n<ol>\n<li data-leveltext=\"%1.\" data-font=\"\" data-listid=\"5\" aria-setsize=\"-1\" data-aria-posinset=\"1\" data-aria-level=\"1\"><span data-contrast=\"auto\">To enable key Rotation,\u00a0go\u00a0to the KMS Console, select the\u00a0key (Primary Key), then select the Key rotation option.<\/span><\/li>\n<\/ol>\n<p><a href=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/Picture65.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-9433\" src=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/Picture65-300x69.png\" alt=\"\" width=\"557\" height=\"128\" \/><\/a><\/p>\n<p><span class=\"TextRun SCXW248645488 BCX0\" lang=\"EN-IN\" xml:lang=\"EN-IN\" data-contrast=\"auto\"><span class=\"NormalTextRun SCXW248645488 BCX0\" data-ccp-parastyle=\"graf\" data-ccp-parastyle-defn=\"{&quot;ObjectId&quot;:&quot;a4de1dfa-ac58-4fbf-b405-f0ef81cf38d8|83&quot;,&quot;ClassId&quot;:1073872969,&quot;Properties&quot;:[134233117,&quot;true&quot;,134233118,&quot;true&quot;,134233614,&quot;true&quot;,201340122,&quot;2&quot;,335559705,&quot;2057&quot;,469769226,&quot;Times New Roman&quot;,469775450,&quot;graf&quot;,469777841,&quot;Times New Roman&quot;,469777842,&quot;Times New Roman&quot;,469777843,&quot;Times New Roman&quot;,469777844,&quot;Times New Roman&quot;,469778129,&quot;graf&quot;,469778324,&quot;Normal&quot;]}\">2. Click on Automatically rotate this KMS key every year option and click Save.<\/span><\/span><span class=\"EOP SCXW248645488 BCX0\" data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\">\u00a0<\/span><\/p>\n<p><a href=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/Picture73.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-9434\" src=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/Picture73-300x41.png\" alt=\"\" width=\"549\" height=\"75\" \/><\/a><\/p>\n<h1 id=\"Conclusion\">Conclusion<\/h1>\n<p><span data-contrast=\"auto\">AWS KMS automatically rotates AWS-managed keys every three years.\u00a0<\/span><span data-contrast=\"auto\">Multi-Region keys allow\u00a0us\u00a0to move encrypted data between regions without having to decrypt and re-encrypt each one with a different key.\u00a0Please share your valuable feedback in the comment section.\u00a0<\/span><span data-ccp-props=\"{&quot;134233117&quot;:true,&quot;134233118&quot;:true}\">\u00a0<\/span><\/p>\n<h1 id=\"&quot;Conclusion\">About CloudThat<\/h1>\n<p>CloudThat provides end-to-end support with all the AWS services. As a pioneer in the Cloud Computing consulting realm, we are\u00a0 AWS (Amazon Web Services) Advanced Consulting Partner, and Training partner. We are on a mission to build\u00a0a robust\u00a0cloud computing ecosystem by disseminating\u00a0knowledge on technological intricacies within the cloud space. Read more about CloudThat\u2019s Consulting and Expert Advisory here:\u00a0<a href=\"https:\/\/www.cloudthat.com\/expert-advisory\/\">https:\/\/www.cloudthat.com\/expert-advisory\/<\/a><\/p>\n<h1>References:<\/h1>\n<p><a href=\"https:\/\/aws.amazon.com\/about-aws\/whats-new\/2021\/06\/kms-multi-region-keys\/\">https:\/\/aws.amazon.com\/about-aws\/whats-new\/2021\/06\/kms-multi-region-keys\/<\/a><\/p>\n","protected":false},"author":236,"featured_media":0,"parent":0,"comment_status":"open","ping_status":"open","template":"","blog_category":[3606,3607],"user_email":"deepaks@cloudthat.com","published_by":"324","primary-authors":"","secondary-authors":"","acf":[],"_links":{"self":[{"href":"https:\/\/www.cloudthat.com\/resources\/wp-json\/wp\/v2\/blog\/9382"}],"collection":[{"href":"https:\/\/www.cloudthat.com\/resources\/wp-json\/wp\/v2\/blog"}],"about":[{"href":"https:\/\/www.cloudthat.com\/resources\/wp-json\/wp\/v2\/types\/blog"}],"author":[{"embeddable":true,"href":"https:\/\/www.cloudthat.com\/resources\/wp-json\/wp\/v2\/users\/236"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cloudthat.com\/resources\/wp-json\/wp\/v2\/comments?post=9382"}],"version-history":[{"count":1,"href":"https:\/\/www.cloudthat.com\/resources\/wp-json\/wp\/v2\/blog\/9382\/revisions"}],"predecessor-version":[{"id":46124,"href":"https:\/\/www.cloudthat.com\/resources\/wp-json\/wp\/v2\/blog\/9382\/revisions\/46124"}],"wp:attachment":[{"href":"https:\/\/www.cloudthat.com\/resources\/wp-json\/wp\/v2\/media?parent=9382"}],"wp:term":[{"taxonomy":"blog_category","embeddable":true,"href":"https:\/\/www.cloudthat.com\/resources\/wp-json\/wp\/v2\/blog_category?post=9382"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}