Manage your OKMS access certificate

View as Markdown

Manage your access certificate for your Data Security products

Objective

The purpose of this guide is to show you the steps to follow to configure and manage the OKMS access certificate for your Data Security products.

Requirements


OVHcloud Control Panel Access

  • Direct link:
  • Navigation path: Identity, Security & Operations > Key Management Service > Select your OKMS domain

Instructions

OKMS access certificate description

To communicate with your OKMS domain, you need an access certificate. This is one of three OKMS authentication methods; certificates are required for KMIP and recommended when mTLS client authentication is needed. For REST API usage, a Personal Access Token or service account is usually simpler to set up.

An access certificate is only valid for the domain for which it was generated.

Warning

Only the certificate creation with a CSR is covered by the PCI-DSS certification.

Create an access certificate from the KMS

OVHcloud Control Panel
OVHcloud API

It's possible to create this certificate from the dedicated entry of the KMS.

In the Access certificates tab, click on Generate an access certificate.

Create a certificate

The first part of the form allows you to precise its validity duration, choose signature algorithm, and providing or not your Certificate Signing Request (CSR) in case you have your own private key.

Without providing a private key

If you do not provide a CSR, OVHcloud will generate the certificate and a private key as well.

Create a certificate

With a CSR

If you own your own private key, it's possible to use it with a CSR.

Create a certificate

The second part of the form allows you to specify the OVHcloud identities associated with the certificate used to calculate access rights via the OVHcloud IAM.

It is possible to add the root identity to the certificate so as not to be constrained by the OVHcloud IAM.

Create a certificate

You then need to download the private key of the certificate.

Danger

The private key will no longer be accessible at a later stage. If you lose it, you will need to regenerate a certificate.

Warning

The privateKeyPEM field needs to be edited so that all instances of \n are replaced by carriage returns.

Create a certificate

Finally it's possible to download the public key of the certificate from the dashboard.

Create a certificate

Go further

Using the OVHcloud KMS with your data.

Join our community of users.

Was this page helpful?