Creating Keys
This section describes steps to create an encryption key using the CTE API.
Overview
Keys in a CTE policy must fulfill the following conditions. The keys should:
- Have the CTE Clients group permissions
Be exportable
Be non-versioned/versioned
Be of the type "CBC_CS1"
- Have metadata with the following details:
CTE supports standard policies.
Keys for Standard Policies
- Standard policies support only non-versioned keys.
- CTE Clients group should have the Read Key and Export Key permissions.
- Standard policies support "CBC_CS1" keys.
API
Sample
Deleting CTE Keys
A CTE key cannot be deleted if it is being used in a policy.
The CTE Admins and Key Admins group permissions are required to delete a CTE key.