SAP HYOK keystores
This section describes how to manage the SAP HYOK keystores.
Creating SAP HYOK keystores
Creation of a keystore requires an SAP tenant ID, keystore URL hostname, and SAP certificate. To create an SAP HYOK keystore:
Open the Cloud Key Manager application.
In the left pane, click Services > SAP HYOK. The SAP HYOK page is displayed.
Click the SAP HYOK Keystores tab.
Click Create Keystore. The General Info tab of the Create SAP HYOK Keystore screen is displayed.
General Info
Enter Name.
(Optional) Enter Description.
Click Next. The Configure Keystore tab is displayed.
Configure Keystore
Enter SAP Tenant ID.
Enter Keystore URL Hostname.
Note
Enable or disable audit recording of successful operations within an external keystore. The default value is false.
(Optional) Enable SAP Enable success audit events.
Add a SAP Certificate. You can use the following options to add the SAP Certificate.
File Upload: Select and upload the certificate (in PEM format).
Text: Select and paste the certificate content.
Note
You can create and download the SAP certificate from the SAP Data Custodian portal.
Click Next. The Review and Create tab is displayed.
Review and Create
This screen shows the key details that you have provided. These details are divided into GENERAL INFO and CONFIGURE KEYSTORE sections.
Before creating the keystore, review all details. After the keystore is added, certain features will no longer be editable.
Review the keystore details displayed on the screen.
If details are incorrect or you want to make any changes, click Edit next to the GENERAL INFO and CONFIGURE KEYSTORE sections, and update details. Alternatively, click Back and make changes, as appropriate.
Click Create. A success message is displayed on the screen.
Click Close. The newly created keystore is displayed in the list of SAP HYOK keystores.
Viewing SAP HYOK keystores
To view the list of the available SAP HYOK Keystores:
Open the Cloud Key Manager application.
In the left pane, click Services > SAP HYOK. The SAP HYOK page is displayed.
Click the SAP HYOK Keystores tab. The list of added SAP HYOK keystores is displayed. The tab displays the following details:
Column Description Name Name of the SAP HYOK keystore. Keystore URL Hostname Hostname for the SAP HYOK keystore URL. Keystore URL URL of the keystore. Status Status of the keystore. The status can be:
• Active
• InactiveBlock Indicates whether the keystore is blocked or unblocked. Tenant ID of the SAP tenant. Creation Date Time when the keystore is created. Last Updated Time when the keystore is updated. Description Description of the keystore.
To view the custom columns, click the Customize View () icon, select the desired option, and click OK.
Viewing and editing details of an SAP HYOK keystore
To view or edit the details of an SAP HYOK keystore:
Open the Cloud Key Manager application.
In the left pane, click Services > SAP HYOK. The SAP HYOK page is displayed.
Click the SAP HYOK Keystores tab. The list of added SAP HYOK keystores is displayed.
Click the Name link of the desired SAP HYOK keystore.
Alternatively, click the overflow icon (
) corresponding to the desired SAP HYOK keystore, and click View/Edit. The SAP HYOK Keystore page is displayed.
The SAP HYOK Keystore page shows additional details of the selected keystore under the ENDPOINT KEYS, GENERAL INFORMATION, KEYSTORE CONFIGURATION, and ACCESS CONTROL sections. Expand each section to view and edit their details.
ENDPOINT KEYS
Expand the ENDPOINT KEYS section.
The list of endpoint associated with the keystore is displayed. To manage these endpoints, refer to SAP HYOK Endpoints.
GENERAL INFORMATION
Expand the GENERAL INFORMATION section.
(Optional) Update the name of the SAP HYOK keystore in the Name field.
(Optional) Update the description of the SAP HYOK keystore in the Description field.
Click Update.
KEYSTORE CONFIGURATION
Expand the KEYSTORE CONFIGURATION section.
(Optional) Enter a new Keystore URL Hostname to use a different URL hostname.
(Optional) Enable or disable SAP Enable success audit events.
Note
Enable or disable audlt recording of successful operations within an external keystore. The default value is false.
(Optional) Update the SAP Certificate. You can use the following options to update the SAP Certificate.
File Upload: Select and upload the certificate (in PEM format).
Text: Select and paste the certificate content.
Note
Create and download this certificate from SAP Data Custodian Portal Key Management Service > Configuratiom > Thales CipherTrust Manager.
Click Update.
ACCESS CONTROL
Refer to Managing User Permissions on SAP HYOK Keystore for details.
Managing User permissions on SAP HYOK keystore
To work with the external resources, users/groups must have the minimum set of permissions that allow them to use the SAP HYOK keystores.
Note
Only the users who are member of the CCKM Users group will be granted permissions to perform operations on SAP HYOK keystores.
Users with the following characteristics can perform operations on SAP HYOK keystores:
Users in the
CCKM Admins
groupUsers in the
Admin
groupUsers who are administrators for a domain
Users who are in the
CCKM Users
group and which have had a CCKM Admin assign permissions through the UI or the/v1/cckm/sap/ekm/keystores/{id}/update-acls
endpoint in the REST API.
Adding permissions for a User/Group
To add permissions for a user/group:
Open the Cloud Key Manager application.
In the left pane, click Services > SAP HYOK. The SAP HYOK page is displayed.
Click the SAP HYOK Keystores tab. The list of added SAP HYOK keystores is displayed.
Click the Name link of the desired SAP HYOK keystore.
Alternatively, click the overflow icon (
) corresponding to the desired SAP HYOK keystore, and click View/Edit. The SAP HYOK Keystore page is displayed.
Expand the ACCESS CONTROL section.
Click Assign User/Group. The Assign User/Group dialog box is displayed.
Select the desired user or group from the User/Group drop-down list.
Click Save.
The newly added user/group is displayed under Name in the ACCESS CONTROL section.
CCKM allows the following operations on the SAP HYOK keystores:
View Keys, Add Key, Delete Key.
Refresh Domain.
You can now grant additional permissions to the user/group, as appropriate. Refer to Granting Permission to Perform an Operation for details.
Granting permission to perform an operation
To grant permissions to the user or group to perform any of the above mentioned operations:
In the ACCESS CONTROL section, select the check box under the desired operation corresponding to the desired users or groups.
Click Update.
A success message is displayed on the screen.
To revoke permissions from a user/group, refer to Removing a Permission for details.
Removing a permission
To remove a permission assigned to a user or group:
In the ACCESS CONTROL section, clear the check box under the desired operation corresponding to the desired users or groups.
Click Update.
A success message is displayed on the screen.
Removing permission from a User/Group
To remove current permissions assigned to the user/group:
In the ACCESS CONTROL section, under Unassign, click the X button corresponding to the desired user/group.
On the Remove User / Remove Group screen, click Remove.
Note
Removing this user/group will remove all permissions currently assigned to the user/group.
Click Remove to confirm the action. To cancel the action, click Keep It.
A success message is displayed on the screen.
Blocking an SAP HYOK keystore
You can block a keystore to deny all proxy API requests from both the keystore and its endpoints. To block an SAP HYOK keystore:
Open the Cloud Key Manager application.
In the left pane, click Services > SAP HYOK. The SAP HYOK page is displayed.
Click the SAP HYOK Keystores tab. The list of added SAP HYOK keystores is displayed.
Click the overflow icon (
) corresponding to the desired SAP HYOK keystore.
Click Block. The Block Keystore dialog box is displayed.
Click Block to confirm the action.
The keystore is blocked successfully. The state of the keystore changes to Blocked.
Unblocking an SAP HYOK keystore
You can block a keystore to accecpt all proxy API requests from both the keystore and its endpoints. To block an SAP HYOK keystore:
Open the Cloud Key Manager application.
In the left pane, click Services > SAP HYOK. The SAP HYOK page is displayed.
Click the SAP HYOK Keystores tab. The list of added SAP HYOK keystores is displayed.
Click the overflow icon (
) corresponding to the desired SAP HYOK keystore.
Click Unblock. The Unblock Keystore dialog box is displayed.
Click Unblock to confirm the action.
The keystore is unblocked successfully. The state of the keystore changes to Unblocked.
Deleting an SAP HYOK keystore
You can delete an archived keystore that has no endpoints from the CCKM. To delete an SAP HYOK keystore:
Open the Cloud Key Manager application.
In the left pane, click Services > SAP HYOK. The SAP HYOK page is displayed.
Click the SAP HYOK Keystores tab. The list of added SAP HYOK keystores is displayed.
Click the overflow icon (
) corresponding to the desired SAP HYOK keystore.
Click Delete. The Delete Keystore dialog box is displayed.
Note
The keystore can only be deleted if it does not contain any SAP HYOK Endpoints.
Select I wish to delete key material.
Click Delete.
You will see a message that the keystore is deleted successfully.
Archiving an SAP HYOK keystore
Archiving transitions a keystore to an intermediate state, a prerequisite for its deletion. When a keystore is archived, its associated endpoints are also archived, and a CCKM license is released.
To archive an SAP HYOK Endpoint:
Open the Cloud Key Manager application.
In the left pane, click Services > SAP HYOK. The SAP HYOK page is displayed.
Click the SAP HYOK Keystores tab. The list of added SAP HYOK keystores is displayed.
Click the overflow icon (
) corresponding to the desired SAP HYOK keystore.
Click Archive. The Archive Keystore dialog box is displayed.
Select I wish to archive this keystore.
Click Archive.
You will see a message that the keystore is archived successfully. The state of the keystore changes to archived.
Recovering an SAP HYOK keystore
You can recover an archived keystore. To recover an SAP HYOK Keystore:
Note
Recovering an archived SAP keystore consumes a CCKM license unit. This process does not automatically recover its previously associated endpoints; you must recover them individually. Refer to Recovering an SAP HYOK endpoint for details.
To recover an SAP HYOK Keystore:
Open the Cloud Key Manager application.
In the left pane, click Services > SAP HYOK. The SAP HYOK page is displayed.
Click the SAP HYOK Keystores tab. The list of added SAP HYOK keystores is displayed.
Click the overflow icon (
) corresponding to the desired SAP HYOK keystore.
Click Recover. The Recover Keystore dialog box is displayed.
Click Recover.
You will see a message that the keystore is recovered successfully.