GUI

  1. Open Key Management Service > Customer managed keys > Create key.

  2. Under Key type click Symmetric.

  3. Click Advanced options and select External.

  4. Tick the checkbox I understand the security, availability, and durability implications of using an imported key.

  5. Click Next.

  6. Type the CMK's Alias.

  7. Optionally, type the CMK's Description and add Tags.

  8. Click Next.

  9. From the list offered, choose the Key administrators.

  10. If you want to allow the administrators to delete this key, tick the Key deletion checkbox.

  11. Click Next.

  12. From the list offered, choose the IAM users and roles that can use the CMK in cryptographic operations.

  13. If necessary, add Other AWS accounts to the list.

  14. Click Next.

  15. Review and edit the key policy as necessary.

  16. Click Finish.

If the creation of the CMK is successful, the following image will appear at the end of your screen:

tmpf_993tyf.jpg

Successful creation of the CMK