From the course: Complete Guide to AWS Security and Compliance Management

Unlock this course with a free trial

Join today to access over 25,300 courses taught by industry experts.

Creating a multi-region KMS key

Creating a multi-region KMS key

- [Instructor] Now that we've configured a KMS key with the multi-region option, let's go ahead and enable additional regions in which this KMS key can be used. All right, within the Customer Managed Key section of KMS, I can see the key that we just created, the engineering-admin key. Clicking into it, I go to the Regionality tab. Note that it is a multi-region primary key without any replicas. Since I want to create new replicas now, I'll go ahead and click the Create New Replica Keys button. At this point, what I need to do is identify the region or regions in which I want to be able to use this key. Since we are doing data protection in Mumbai, I add that to the list. We're also planning on doing operations in Ohio, so I'll add that region as well. Wonderful, that looks good, so I go ahead and click the Next button. It's important to note that at any time, I could go back and add or remove regions. The label screen is pre-populated with the alias for the keys that I'm replicating.…

Contents