This guide provides information on how to configure Oracle Cloud Infrastructure (OCI) to work with the Utimaco Enterprise Secure Key Manager (ESKM) for Bring Your Own Key (BYOK) scenarios. It describes the features and configuration steps in OCI and ESKM that are necessary to establish and validate the integration.
The guide describes the configuration required to securely create and manage cryptographic keys in ESKM and upload them to Oracle Cloud Infrastructure Key Management Service (OCI KMS), where they can be used by OCI services for encryption-at-rest.
This guide focuses only on the configuration and integration aspects required for the OCI–ESKM BYOK scenario. It does not provide general installation or administration procedures for OCI or ESKM beyond those required to establish the integration.
For more information on installing and configuring the Utimaco Enterprise Secure Key Manager, refer to the applicable Utimaco Enterprise Secure Key Manager installation and administration documentation.
Target Audience
This guide is intended for Oracle Cloud Infrastructure (OCI) and Utimaco Enterprise Secure Key Manager (ESKM) administrators responsible for configuring and managing the integration between OCI and ESKM.
Purpose of the Integration
The purpose of this integration is to enable Oracle Cloud Infrastructure (OCI) services to use customer-controlled cryptographic keys managed through the Utimaco Enterprise Secure Key Manager (ESKM).
In the BYOK model, cryptographic keys are created and securely managed in ESKM before being uploaded to Oracle Cloud Infrastructure Key Management Service (OCI KMS). This allows organizations to maintain control over the generation and lifecycle management of their cryptographic keys while making the keys available to OCI services for encryption-at-rest.
The integration aims to:
-
Enable OCI services to use customer-controlled cryptographic keys for encryption-at-rest.
-
Enable secure upload of cryptographic keys from ESKM into OCI KMS.
-
Provide centralized key management and lifecycle control through Utimaco ESKM.
-
Maintain secure authentication and communication between ESKM and OCI.
-
Support enterprise security and compliance requirements through controlled management of cryptographic material.
Abbreviations
|
Abbreviation |
Meaning |
|---|---|
|
API |
Application Programming Interface |
|
BYOK |
Bring Your Own Key |
|
CA |
Certificate Authority |
|
ESKM |
Enterprise Secure Key Manager |
|
HSM |
Hardware Security Module |
|
IAM |
Identity and Access Management |
|
KMS |
Key Management Service |
|
OCID |
Oracle Cloud Identifier |
|
OCI |
Oracle Cloud Infrastructure |
|
RSA |
Rivest–Shamir–Adleman |
|
TLS |
Transport Layer Security |
Abbreviations
Document Conventions
The following conventions are used in this guide:
|
Convention |
Use |
Example |
|---|---|---|
|
Bold |
Items of the Graphical User Interface (GUI), e.g., menu options |
Press OK |
|
|
Code that is given for explanation or as an example, file paths |
|
|
Italic |
References and important terms |
See Sample Chapter in the CryptoServer - Sample Manual |
Document conventions
We use special icons to highlight the most important notes and information.
Here you will find important safety information that should be followed.
Here you will find additional notes or supplementary information.
This message indicates the expected result after the successful execution of an instruction.