1
From the main Google Cloud dashboard, enter
Key Management in the search bar, and select the Key Management - Security service.2
Select the Key Ring you created in earlier.
3
Select [ Create Key ]. This opens the key creation wizard.
4
Enter a name for the key. This key name does not need to match the name of the key created in CryptoHub.
5
Select External as the protection level for the key.
6
Select either via internet or via VPC as the EKM connection type.
7
Select [ Continue ].
8
Enter the Key URI. You can copy the Key URI by selecting the Key URI button for the key in CryptoHub.
9
Select [ Continue ] again. This enables you to select Symmetric encrypt/decrypt or Asymmetric sign in the Purpose drop-down menu.
10
Select [ Create ] to create the externally managed key.
The key status should change to a green checkmark, confirming the key is successfully synced with the key material stored in CryptoHub.

