The following limitations currently exist:
AWS currently supports only 256-bit AES keys.
Amazon recommends a round-trip time latency of under 35 milliseconds between the AWS region and the CSP Vault.
The maximum request timeout in KMS is set to 250 milliseconds.
External key stores are supported in MOST AWS Regions in which AWS KMS is supported. Prior to selecting the region, make sure XKS is supported in that region.
Only the XKS Public endpoint connection option is supported.