Configure and upload your customer supplied key
You can use your own customer-supplied key instead of using the ServiceNow® system-generated keys.
Before you begin
Role required: security_admin and sn_kmf.cryptographic_manager or sn_kmf.admin
If you’re NOT supplying your own keys, you don’t need to perform this procedure. To create a cryptographic module with ServiceNow® keys, go to Create a cryptographic module or Create cryptographic module for Field Encryption.
Note: This procedure only applies to Field Encryption Enterprise functionality. See Activate Field Encryption for more information.
Important: You can’t revoke a customer supplied key.
Procedure
Navigate to All > System Security > Field Encryption > Field Encryption Experience.
Select View module details on the Field Encryption module.
Select Encryption Keys and Select and Continue for the Bring-your-own Key option.
Select Download wrapping key and Next.
Follow the required online steps and select the I completed the online steps box followed by Done and continue to the next step.
Upload the wrapped encryption key and the import token downloaded with the wrapped key, enter a name for the encryption key, and select Complete provisioning.
What to do next
Now that you have finished configuring your cryptographic module with your customer-supplied key, move on to Create a module access policy
Parent Topic:Using customer-supplied keys with Field Encryption Enterprise
Parent Topic:Using customer supplied keys with Column Level Encryption Enterprise