/v0/key-encrypt/external/<crypto-space name>
The URL must start with
/v0. Otherwise, Google appends it to the returned Crypto Space path, resulting in a mismatching URL check.Create a Google Crypto Space
Perform the following steps to create a new Google Crypto Space on the KMES Series 3:On the Info tab of the Google Crypto Space window, enter a name for the Google Crypto Space. Then, set the following permissions:
| Key type | Permissions |
|---|---|
| Symmetric |
|
| Asymmetric |
|
If you use a VPC connection between Google Cloud and the KMES Series 3, select the GET_INFO permission.
On the Justifications tab, select one of the following access reasons:
- REASON_UNSPECIFIED
- CUSTOMER_INITIATED_SUPPORT
- GOOGLE_INITIATED_SERVICE
- THIRD_PARTY_DATA_REQUEST
- GOOGLE_INITIATED_REVIEW
- CUSTOMER_INITIATED_ACCESS
- GOOGLE_INITIATED_SYSTEM_OPERATION
- REASON_NOT_EXPECTED
- MODIFIED_CUSTOMER_INITIATED_ACCESS
- MODIFIED_GOOGLE_INITIATED_SYSTEM_OPERATION
- GOOGLE_RESPONSE_TO_PRODUCTION_ALERT
Select [ OK ] to close the successful creation message. The Google Crypto Space window now has additional tabs for Symmetric and Asymmetric keys.

