Go to the Dashboard
Perform the following steps to go to the Google Cloud Key Management Dashboard:From the main Google Cloud dashboard, enter
Key Management in the search bar at the top of the page.Create a new key ring
Perform the following steps to create a new key ring:In the Create key ring wizard, enter a name for the key ring.
Key ring names can only contain letters, numbers, underscores (_), and hyphens (-). You can’t rename or delete them.
Select Region as the Location type(EKM does not support Multi-region). In the drop-down menu, select the Google region where you want to create the key ring.
Select [ Create ].Note the following regarding the key ring location:
- Cloud EKM must be able to access your keys quickly to prevent errors. When creating a Cloud EKM key, choose a Google Cloud location that is geographically near the location of the KMES Series 3.
- You can use Cloud EKM in any Google Cloud location supported for Cloud KMS, except for global.
Find the Service Account email address
After you create the Key Ring, the browser redirects to the key creation wizard. Perform the following steps to find the Service Account email address:Note the service account email address in the Key material section. The service account email address is copied later to the email field of the identity that Google uses to interact with the KMES Series 3.You return to this dialog in the Google Cloud dashboard after creating a Google Crypto Space on the KMES in an upcoming section.

