tencent cloud

DocumentaçãoKey Management Service

Creating a Root Key

Download
Modo Foco
Tamanho da Fonte
Última atualização: 2026-07-24 11:55:50
Traduzido por IA

Scenarios

You can create a CMK in the Tencent Cloud KMS (Compliant) console or via the CreateKey API. After creation, you can enable, disable, rotate, or manage permissions for the CMK. This document describes how to create a CMK through the console.

Operation Steps

1. Log in to the KMS (Compliant) console. In the left sidebar, click Key Management > Root Key.
2. On the root key management page, click Create Root Key. In the configuration box that pops up, enter the following information:
Parameter
Description
Key Name
(Required) It represents the UUID of the key within the region.
The key name can only contain letters, digits, and the characters _ and -, and cannot start with "KMS-".
Description
(Optional) It is used to describe the type of data you plan to protect or the application you intend to use with the CMK.
Tag
(Optional) Tag is a resource management tool provided by Tencent Cloud. Users can categorize, search for, and aggregate keys by adding tags.
Key usage
(Required)
Select Symmetric Encryption/Decryption, Asymmetric Encryption/Decryption, or Asymmetric Signature Verification.
Encryption algorithm
When the Key Purpose is Asymmetric Encryption/Decryption or Asymmetric Signature Verification, the following encryption algorithms can be selected:
Asymmetric Encryption/Decryption: SM2, RSA_2048, Kyber_AES.
Asymmetric Signature/Verification: SM2, RSA_2048, RSA_3072, ECC, ECDSA384_SHA384, Dilithium.
When the Key Purpose is Symmetric Encryption/Decryption, the encryption algorithm cannot be selected. By default, it is SM4 for the Chinese mainland and AES_256 for regions outside the Chinese mainland (including Hong Kong (China), Macao (China), and Taiwan (China)).
Key Material Source
(Required)
Select the key generation method: KMS-generated or user-owned key import.
Note
When the Key Material Source is External, the Key Purpose should be Symmetric Encryption/Decryption.
4. After clicking OK, you will return to the key list. The newly created key will appear at the top of the list.



Ajuda e Suporte

Esta página foi útil?

comentários