Google Cloud EKM (External Key...
Configure the VirtuCrypt Intelligence Portal (VIP)
5 min
with the google cloud kms setup complete, this section focuses on configuring the {{vc}} side of the integration it shows how to establish the necessary user identity, assign appropriate roles for google key management operations, and create the symmetric encryption key that {{vc}} manages externally but is accessible to google cloud services this configuration ensures secure authentication and proper key management permissions between the two platforms before proceeding with the steps in this section, you must create a new vip user inside your {{vc}} account the name of this user must match the service account email that google ekm provided in the previous section (such as service 54255661635\@gcp sa ekms iam gserviceaccount com ) reach out to the {{futurex}} xceptional support team to request that this user be added to your account log in to the ekm service in vip perform the following steps to log in to the enterprise key management service in vip log in at https //vip virtucrypt com/login with an account identity that is authorized to access the enterprise key management service created for integration with google ekm after you log in to the vip, select the google ekm service, and select \[ manage ] in the upper right corner of the page create a new identity perform the following steps to create a new identity and assign it the google key management role in the google ekm service, go to the service users page in the left side menu select \[ add identity ] in the upper right corner of the page in the vip user field, select the vip user that you added to your {{vc}} account at the beginning of this section (such as service 54255661635\@gcp sa ekms iam gserviceaccount com ) in the roles field, select the google key management role select \[ submit ] to save the changes create a new symmetric key to create a symmetric key, add a new key group and then create the key add a new key group perform the following steps to add a key group go to the symmetric keys page in the left side menu, and select \[ add key group ] at the top of the page specify a key group name and the key retrieval algorithm to use select \[ ok ] to save a message should appear at the top of the screen stating that the key group was created successfully create a new symmetric key perform the following steps to create a symmetric key select the key group that you just created, and select \[ add key ] in the general tab, perform the following steps select random as the encryption mode select data encryption key as the key type choose one of the aes algorithms enter a name for the key using the aes algorithm enables setting key usages for the key the key usages for data encryption keys in {{vc}} are encrypt/decrypt therefore, google ekm can use the same key for encryption and decryption in the validity tab, set the desired validity start and end dates select \[ ok ] to save if successful, a message appears at the top of the screen stating that the key was created successfully