Set Up Key Management Service for Data Encryption¶
All new warehouses can be created with data at rest encryption enabled. There are two options for Key Management Services (KMS) behind the data encryption:
- Actian-managed encryption
- Your customer-managed KMS
These services use a master key encryptionkey to encrypt and decrypt a data encryption key for locking and unlocking the Actian warehouse.
Actian Data Platform supports the following external KMSs:
- AWS Key Management Service (AKMS), see Set Up the AWS Key Management Service (AKMS)
Actian Data Platform does not support external keys from Google Cloud Key Management or Microsoft Azure Key Vault.
Note
To use your external KMS for data encryption, you must set up the external key before creating any warehouses.
Important
IMPORTANT!Any warehouses created using the Actian-managed encryption key or your customer-managed external KMS master key always use that method for data key decryption. Once an encryption method is assigned at warehouse creation, it cannot be changed subsequently.