To create a Cryptographic Security Platform Vault node in AWS, you need to launch a Entrust Cryptographic Security Platform Vault for AWS instance and then configure that instance using SSH.
After the first Cryptographic Security Platform Vault node is configured, you can then add additional nodes from other AWS availability zones or regions, or from other environments such as VMware vSphere or Microsoft Azure. All configuration information from the first node is copied to any subsequent nodes that you add to the cluster.
Note:
CSP Vault now supports AWS Instance Metadata Service Version 2 (IMDSv2) to access EC2 instance metadata.
CSP Vault does not support SSM manager. To access the console, use the EC2 console.
To create a Cryptographic Security Platform Vault cluster in AWS, perform the following tasks:
Step | Task | Details |
|---|---|---|
1 | Launch a Entrust Cryptographic Security Platform Vault for AWS instance that will become the initial Cryptographic Security Platform Vault node in the cluster. | |
2 | Associate an Elastic IP (EIP) address with the instance. | Associating an Elastic IP Address with the CSP Vault Instance. |
3 | Configure the first Cryptographic Security Platform Vault node and initialize the Cryptographic Security Platform Vault webGUI. | |
4 | If desired, deploy additional Cryptographic Security Platform Vault nodes in AWS. | |
5 | Configure the additional nodes and join them to the existing cluster. |