About This Guide

This guide provides information on how to configure Oracle Cloud Infrastructure (OCI) to work with the Utimaco Enterprise Secure Key Manager (ESKM) for Bring Your Own Key (BYOK) scenarios. It describes the features and configuration steps in OCI and ESKM that are necessary to establish and validate the integration.

The guide describes the configuration required to securely create and manage cryptographic keys in ESKM and upload them to Oracle Cloud Infrastructure Key Management Service (OCI KMS), where they can be used by OCI services for encryption-at-rest.

This guide focuses only on the configuration and integration aspects required for the OCI–ESKM BYOK scenario. It does not provide general installation or administration procedures for OCI or ESKM beyond those required to establish the integration.

For more information on installing and configuring the Utimaco Enterprise Secure Key Manager, refer to the applicable Utimaco Enterprise Secure Key Manager installation and administration documentation.

Target Audience

This guide is intended for Oracle Cloud Infrastructure (OCI) and Utimaco Enterprise Secure Key Manager (ESKM) administrators responsible for configuring and managing the integration between OCI and ESKM.

Purpose of the Integration

The purpose of this integration is to enable Oracle Cloud Infrastructure (OCI) services to use customer-controlled cryptographic keys managed through the Utimaco Enterprise Secure Key Manager (ESKM).

In the BYOK model, cryptographic keys are created and securely managed in ESKM before being uploaded to Oracle Cloud Infrastructure Key Management Service (OCI KMS). This allows organizations to maintain control over the generation and lifecycle management of their cryptographic keys while making the keys available to OCI services for encryption-at-rest.

The integration aims to:

  • Enable OCI services to use customer-controlled cryptographic keys for encryption-at-rest.

  • Enable secure upload of cryptographic keys from ESKM into OCI KMS.

  • Provide centralized key management and lifecycle control through Utimaco ESKM.

  • Maintain secure authentication and communication between ESKM and OCI.

  • Support enterprise security and compliance requirements through controlled management of cryptographic material.

Abbreviations

Abbreviation

Meaning

API

Application Programming Interface

BYOK

Bring Your Own Key

CA

Certificate Authority

ESKM

Enterprise Secure Key Manager

HSM

Hardware Security Module

IAM

Identity and Access Management

KMS

Key Management Service

OCID

Oracle Cloud Identifier

OCI

Oracle Cloud Infrastructure

RSA

Rivest–Shamir–Adleman

TLS

Transport Layer Security

Abbreviations

Document Conventions

The following conventions are used in this guide:

Convention

Use

Example

Bold

Items of the Graphical User Interface (GUI), e.g., menu options

Press OK 

Monospaced

Code that is given for explanation or as an example, file paths

chsm-create

Italic

References and important terms

See Sample Chapter in the CryptoServer - Sample Manual

Document conventions

We use special icons to highlight the most important notes and information.

Here you will find important safety information that should be followed.

Here you will find additional notes or supplementary information.

This message indicates the expected result after the successful execution of an instruction.