Version: v0.25.0 (Latest)
Register an existing Azure key (BYOK)
Step 3 of 5 in Connect Azure KMS with BYOK and BYOC.
Check what the provider can do before depending on it. Capabilities list the algorithms and operations the provider supports, which is what issuer and verifier signing settings will require.
Loading example...
Register the key by its provider-native alias on the tenant host. No private material is uploaded.
{
"providerId": "customer-azure-vault",
"alias": "credential-signing-key"
}
Loading example...
Read the key back and compare its algorithm, kid and public JWK with what Azure reports.
Loading example...
Registering a reference does not add or change Azure tags. When the provider is shared, a key without the tenant tag is refused even though the provider itself is enabled for the tenant.
Next
Continue with step 4, Register the certificate chain (BYOC).