Add key from an External Key Manager

Add key from an External Key Manager

Overview

Bring Your Own Key (BYOK) is a feature that allows you to use your own key encryption key(KEK) instead of Zoho's KEK. You can add a key either from an External Key Manager (EKM) of your choice or upload an encrypted key manually.

If you choose to provide access to your own KEK from an External key manager, it will be used to encrypt or decrypt the DEKs we provide. This ensures that the data security rests in your control, thus enhancing the security of your organization.
The process is as follows:

  1. After you configure your key in Zoho One, we will send a request to your EKM to have our DEKs encrypted.

  2. The encrypted DEK returned from the EKM will be stored in our in-house KMS.

  3. To decrypt the encrypted DEK, we will send a decrypt request to your EKM using the stored ciphered text and receive plain DEK.

  4. The plain DEK will be cached only for the duration allowed by you, after which we will send encrypt/decrypt requests to EKM again, repeating the entire process.


The steps to add key from EKM vary between the two User Interface versions supported in Zoho One. Select the UI version you use from the tabs below and proceed with the steps that follow.

Spaces UI
Unified UI
Spaces UI
To add key,

Notes
Encryption or decryption of data will not function if the External Key from the External key manager (EKM) is modified or inaccessible.

  1. Sign in to Zoho One , then click Directory icon on the top-right corner.

  2. Click Security.

  3. Click BYOK, then click Setup.

    NotesNote: Click Add key on the right if you already have a key added.

  1. In the Add key screen, enter the Key name, select applications, enable availability key if you want it to be used for data recovery in case of unavailability of the configured key, and choose your key type as External key manager.


    NotesOnly one key can be applied to an app.


  1. Under Key details, provide the necessary details about your key provider.

  • If you select your Key provider as AWS,
    enter the Client ID, Client secret, key ID, and Domain.

  • If you select your Key provider as Google KMS,
    enter the Key ring, Key name, Key version, and Location, upload the Service account key in JSON format, and toggle on Raw encrypt.

  • If you select your Key provider as Thales CTM,
    enter the User name, Password, Key ID, and Domain.

  • If you select your Key provider as Fortanix DSM,
    enter the API key, Key ID, and Domain.

  • If you select your Key provider as HSM, enter the Key name, CKU user password, and HSM label.

  • If you select your Key provider as Futurex, enter the API key, Key ID, and Domain.

 

  1. Select the required cache duration from the drop-down list.

  2. Click Check Key to validate the entered key credentials.

  3. Click Add.


Notes
Note: When configuring BYOK for a specific service, the app will be removed from the default key. The app will be added back to the default key if the particular BYOK key is deleted.

 



Unified UI
To add key,
Notes
Encryption or decryption of data will not function if the External Key from the External key manager (EKM) is modified or inaccessible.
  1. Sign in to Zoho One , then click Directory in the left menu.

  2. Click Security.

  3. Click BYOK, then click Setup.

Note: Click Add key on the right if you already have a key added.



  1. In the Add key screen, enter the Key name, select applications, enable availability key if you want it to be used for data recovery in case of unavailability of the configured key, and choose your key type as External key manager.

NotesOnly one key can be applied to an app.

    1. Under Key details, provide the necessary details about your key provider.

    • If you select your Key provider as AWS,
      enter the Client ID, Client secret, key ID, and Domain.

    • If you select your Key provider as Google KMS,
      enter the Key ring, Key name, Key version, and Location, upload the Service account key in JSON format, and toggle on Raw encrypt.

    • If you select your Key provider as Thales CTM,
      enter the User name, Password, Key ID, and Domain.

    • If you select your Key provider as Fortanix DSM,
      enter the API key, Key ID, and Domain.

    • If you select your Key provider as HSM, enter the Key name, CKU user password, and HSM label.

    • If you select your Key provider as Futurex, enter the API key, Key ID, and Domain.

     

    1. Select the required cache duration from the drop-down list.

    2. Click Check Key to validate the entered key credentials.

    3. Click Add.

     

        Create. Review. Publish.

        Write, edit, collaborate on, and publish documents to different content management platforms.

        Get Started Now


          Access your files securely from anywhere

            Zoho CRM Training Programs

            Learn how to use the best tools for sales force automation and better customer engagement from Zoho's implementation specialists.

            Zoho CRM Training
              Redefine the way you work
              with Zoho Workplace

                Zoho DataPrep Personalized Demo

                If you'd like a personalized walk-through of our data preparation tool, please request a demo and we'll be happy to show you how to get the best out of Zoho DataPrep.

                Zoho CRM Training

                  Create, share, and deliver

                  beautiful slides from anywhere.

                  Get Started Now


                    Zoho Sign now offers specialized one-on-one training for both administrators and developers.

                    BOOK A SESSION







                                Quick LinksWorkflow AutomationData Collection
                                Web FormsEnterpriseOnline Data Collection Tool
                                Embeddable FormsBankingBegin Data Collection
                                Interactive FormsWorkplaceData Collection App
                                CRM FormsCustomer ServiceAccessible Forms
                                Digital FormsMarketingForms for Small Business
                                HTML FormsEducationForms for Enterprise
                                Contact FormsE-commerceForms for any business
                                Lead Generation FormsHealthcareForms for Startups
                                Wordpress FormsCustomer onboardingForms for Small Business
                                No Code FormsConstructionRSVP tool for holidays
                                Free FormsTravelFeatures for Order Forms
                                Prefill FormsNon-Profit

                                Intake FormsLegal
                                Mobile App
                                Form DesignerHR
                                Mobile Forms
                                Card FormsFoodOffline Forms
                                Assign FormsPhotographyMobile Forms Features
                                Translate FormsReal EstateKiosk in Mobile Forms
                                Electronic Forms
                                Drag & drop form builder

                                Notification Emails for FormsAlternativesSecurity & Compliance
                                Holiday FormsGoogle Forms alternative GDPR
                                Form to PDFJotform alternativeHIPAA Forms
                                Email FormsFormstack alternativeEncrypted Forms

                                Wufoo alternativeSecure Forms

                                WCAG

                                          Create. Review. Publish.

                                          Write, edit, collaborate on, and publish documents to different content management platforms.

                                          Get Started Now







                                                            You are currently viewing the help pages of Qntrl’s earlier version. Click here to view our latest version—Qntrl 3.0's help articles.




                                                                Manage your brands on social media


                                                                  • Desk Community Learning Series


                                                                  • Digest


                                                                  • Functions


                                                                  • Meetups


                                                                  • Kbase


                                                                  • Resources


                                                                  • Glossary


                                                                  • Desk Marketplace


                                                                  • MVP Corner


                                                                  • Word of the Day


                                                                  • Ask the Experts


                                                                    Zoho Sheet Resources

                                                                     

                                                                        Zoho Forms Resources


                                                                          Secure your business
                                                                          communication with Zoho Mail


                                                                          Mail on the move with
                                                                          Zoho Mail mobile application

                                                                            Stay on top of your schedule
                                                                            at all times


                                                                            Carry your calendar with you
                                                                            Anytime, anywhere




                                                                                  Zoho Sign Resources

                                                                                    Sign, Paperless!

                                                                                    Sign and send business documents on the go!

                                                                                    Get Started Now




                                                                                            Zoho TeamInbox Resources





                                                                                                      Zoho DataPrep Demo

                                                                                                      Get a personalized demo or POC

                                                                                                      REGISTER NOW


                                                                                                        Design. Discuss. Deliver.

                                                                                                        Create visually engaging stories with Zoho Show.

                                                                                                        Get Started Now








                                                                                                                            • Related Articles

                                                                                                                            • Upload Key

                                                                                                                              Overview Bring Your Own Key (BYOK) is a feature that allows you to use your own key encryption key(KEK) instead of Zoho's KEK. You can add a key either from an External Key Manager (EKM) of your choice or upload an encrypted key manually. If you ...
                                                                                                                            • Overview

                                                                                                                              Encryption is used to secure data by replacing plain text with ciphered text, so that only the intended recipient can understand its contents. Any form of data is initially encrypted at rest using Data Encryption Keys (DEK). The DEKs are further ...
                                                                                                                            • Edit, Change and Delete key

                                                                                                                              The steps to edit, change, and delete key vary between the two User Interface versions supported in Zoho One. Select the UI version you use from the tabs below and proceed with the steps that follow. Spaces UI Unified UI Spaces UI Change Key: Sign in ...
                                                                                                                            • Add department

                                                                                                                              In the mobile application: For iOS devices: Open the Zoho One app on your mobile device. Tap at the bottom, then tap CREATE GROUP. Tap Department, then enter the Department name, Group email, and Department description. Tap Next, assign the ...
                                                                                                                            • Device Management

                                                                                                                              Managing your employees' devices is just as crucial as monitoring their online identities when it comes to making sure they are handling company data responsibly. This is where device management comes in. Zoho One has device management features that ...
                                                                                                                              Wherever you are is as good as
                                                                                                                              your workplace

                                                                                                                                Resources

                                                                                                                                Videos

                                                                                                                                Watch comprehensive videos on features and other important topics that will help you master Zoho CRM.



                                                                                                                                eBooks

                                                                                                                                Download free eBooks and access a range of topics to get deeper insight on successfully using Zoho CRM.



                                                                                                                                Webinars

                                                                                                                                Sign up for our webinars and learn the Zoho CRM basics, from customization to sales force automation and more.



                                                                                                                                CRM Tips

                                                                                                                                Make the most of Zoho CRM with these useful tips.



                                                                                                                                  Zoho Show Resources