Creating a Keystore

You can create dedicated key stores and manage them on the console. A keystore is disabled by default.

Prerequisites

You have obtained the CA certificate of the HSM cluster.

Constraints

So far, keystore management is available in CN North-Beijing1, CN North-Beijing4, CN East-Shanghai1, CN East-Shanghai2, and CN South-Guangzhou.

Procedure

  1. Log in to the management console.
  2. Click in the upper left corner of the management console and select a region or project.
  3. Click . Choose Security & Compliance > Data Encryption Workshop.
  4. Click the Dedicated Keystore tab and click Create Dedicated Keystore.
  5. In the Create Dedicated Keystore dialog box, configure parameters and click OK. For more information, see Table 1.

    Figure 1 Creating a keystore
    Table 1 Dedicated keystore parameters

    Parameter

    Description

    Example Value

    Alias

    Keystore alias

    Keystore-1234

    Dedicated HSM Cluster

    HSM cluster

    NOTICE:

    A Dedicated HSM cluster must meet the following requirements:

    • The cluster has been activated.
    • The cluster has two or more HSMs.
    • The cluster has not been used to create a dedicated keystore.

    Cluster-1234

    CA Certificate

    CA certificate

    After you select a certificate, the CA certificate content will be automatically generated.

    CA Certificate Content

    PEM code of the certificate

    -

  6. Enable the keystore. It is disabled by default. In the Operation column, click Enable.