Auto Light Dark
Auto Light Dark

Verification and Testing

Functional Testing

Create the Key Reference in OCI

  1. In the OCI Console, open the External Vault created previously.

  2. Go to Keys.

  3. Click Create Key Reference.

image-20261004-170932.png


Create Key Reference

  1. Enter the external key identifier created in the ESKM previously:

    <EXTERNAL_KEY_ID>

image-20261004-171108.png


Key Reference Information

  1. Enter the required algorithm and key length, if requested.

  2. Enter the Key Reference name.

  3. Click Create.

  4. Verify that the Key is created and has the expected status.

image-20261004-171328.png


Key Reference Created

The Key Referece is associated with the key managed by the external KMS. The cryptographic key remains under the control of the external KMS.


Rotate the Key in OCI

  1. In the OCI Console, open the External Vault and select Keys.

  2. Select the HYOK Key Reference and open Key Reference Versions.

  3. Select Rotate Key Reference.

image-20261004-215655.png


Rotate Key Reference

  1. Leave the External Key Version ID field empty.

The External Key Version ID is optional. If a specific key version has already been generated in ESKM, its ID can be entered. If the field is left empty, OCI creates a new Key Reference Version using the latest key version available in the External Key Manager.

  1. Confirm the rotation when prompted.

image-20261004-215729.png


Rotate Key Reference Information

  1. Verify that the new Key Reference Version is displayed as Enabled.

image-20261004-215851.png


Key Reference Rotated

Disable the Key in OCI

  1. In the External Vault, go to Keys.

  2. Select the HYOK Key Reference and open Actions.

  3. Select Disable and confirm the operation.

image-20261004-220116.png

Disable Key Reference

  1. Verify that the Key Reference status changes to Disabled.

image-20261004-220220.png

Key Reference Disabled

A disabled Key Reference cannot be used for cryptographic operations.


Modify the Key in OCI

For HYOK, the key material itself cannot be modified in OCI. To test modification of the OCI-side resource:

  1. In the External Vault, go to Keys.

  2. Select the HYOK Key Reference.

  3. Select Edit Name and modify the available key name.

image-20261004-220926.png

Edit Key Name

  1. Save the changes and verify that the modification is displayed.

image-20261004-221018.png

Key Name Modified


Encrypt with the Key in OCI

  1. In the OCI Console, go to Storage → Block Storage → Block Volumes.

  2. Click Create Block Volume.

image-20261004-221321.png

Create Block Volume

  1. Enter the required volume information.

  2. Under Encryption, select Encrypt using a customer-managed key.

  3. Select the External Vault created previously.

  4. Select the HYOK Key Reference.

image-20261004-221438.png

Select HYOK Key Reference

  1. Click Create.

  2. Verify that the Block Volume is created successfully and that the HYOK Key Reference is displayed as the encryption key.


Delete the Key in OCI

  1. In the External Vault, go to Keys.

  2. Select the HYOK Key Reference and open its actions.

image-20261004-222006.png

Delete Key

  1. Select Delete.

image-20261004-222217.png


Confirm Deletion Schedule

  1. Confirm the deletion and verify that the Key Reference is scheduled for deletion or removed according to its current state.

image-20261004-222301.png


Key Pending Deletion

Deleting the Key Reference in OCI does not delete the corresponding key in ESKM. the external key remains available in the external KMS.

Logs and Validation Steps

The ESKM logs can be used to verify the operations performed during the OCI-HYOK integration and to confirm the successful upload of the key to OCI.

  1. In the ESKM Management Console, click Device > Logs & Statistics > Log Viewer > REST.

  2. In the ESKM Management Console, click Device > Logs & Statistics > Log Viewer > Audit.

  3. In the ESKM Management Console, click Device > Logs & Statistics > Log Viewer > System.

  4. Review the REST, Audit, and System logs for the operations performed during the OCI-HYOK integration.

  5. In the Audit log, verify that the key upload operation was successfully completed.

image-20261004-221831.png

ESKM HYOK Logs

The successful Audit log entry confirms that the key upload operation was completed by ESKM. Together with the key being visible in the OCI Vault, this validates the successful transfer of the key as part of the OCI-HYOK integration.