STACKIT KMS allows organizations to create, store, and manage cryptographic keys for cloud data encryption.
Service Overview
Section titled “Service Overview”- Envelope Encryption: Generates local DEKs protected by KMS-stored Master Keys (KEKs).
- Bring Your Own Key (BYOK): Securely import custom key pairs using wrapping key protocols.
- Sovereign Execution: Cryptographic key operations run inside certified German data centers.
Technical Details
Section titled “Technical Details”- Supported Algorithms: AES-256-GCM, RSA (2048/3072/4096), ECDSA (P256/P384/P521), and HMAC.
- Service Native: Directly integrated with STACKIT Block Storage and database encryption engines.
Algorithms
Section titled “Algorithms”The values below come from the STACKIT documentation and update themselves.
Symmetric Encrypt Decrypt
- AES 256 GCM: This will use the Advanced Encryption Standard (AES) with a 256 bit key in Galois Counter Mode (GCM)
Asymmetric Encrypt Decrypt
- RSA 2048 OAEP SHA256: This will use a 2048 bit RSA key with Optimal Asymmetric Encryption Padding (OAEP) using a SHA256 digest.
- RSA 3072 OAEP SHA256: This will use a 3072 bit RSA key with Optimal Asymmetric Encryption Padding (OAEP) using a SHA256 digest.
- RSA 4096 OAEP SHA256: This will use a 4096 bit RSA key with Optimal Asymmetric Encryption Padding (OAEP) using a SHA256 digest.
- RSA 4096 OAEP SHA512: This will use a 4096 bit RSA key with Optimal Asymmetric Encryption Padding (OAEP) using a SHA512 digest.
Asymmetric Sign Verify
- ECDSA P256 SHA256: This will use the ECDSA algorithm based on the P256 curve (a.k.a.
secp256r1). - ECDSA P384 SHA384: This will use the ECDSA algorithm based on the P384 curve (a.k.a.
secp384r1). - ECDSA P521 SHA512: This will use the ECDSA algorithm based on the P521 curve (a.k.a.
secp521r1).
Message Authentication Code
HMAC SHA256: This will use a 256 bit key using a SHA256 digest
HMAC SHA384: This will use a 384 bit key using a SHA384 digest
HMAC SHA512: This will use a 512 bit key using a SHA512 digest
Wrap Symmetric Key
RSA 2048 OAEP SHA256: This will use a 2048 bit RSA key with Optimal Asymmetric Encryption Padding (OAEP) using a SHA256 digest.
RSA 3072 OAEP SHA256: This will use a 3072 bit RSA key with Optimal Asymmetric Encryption Padding (OAEP) using a SHA256 digest.
RSA 4096 OAEP SHA256: This will use a 4096 bit RSA key with Optimal Asymmetric Encryption Padding (OAEP) using a SHA256 digest.
RSA 4096 OAEP SHA512: This will use a 4096 bit RSA key with Optimal Asymmetric Encryption Padding (OAEP) using a SHA512 digest.
Wrap Asymmetric Key
RSA 2048 OAEP SHA256 with AES 256 Key Wrapping: This will use a 2048 bit RSA wrapping key with Optimal Asymmetric Encryption Padding (OAEP) using a SHA256 digest to encrypt a temporary AES 256 symmetric key that is used to encrypt the actual key material.
RSA 3072 OAEP SHA256 with AES 256 Key Wrapping: This will use a 3072 bit RSA wrapping key with Optimal Asymmetric Encryption Padding (OAEP) using a SHA256 digest to encrypt a temporary AES 256 symmetric key that is used to encrypt the actual key material.
RSA 4096 OAEP SHA256 with AES 256 Key Wrapping: This will use a 4096 bit RSA wrapping key with Optimal Asymmetric Encryption Padding (OAEP) using a SHA256 digest to encrypt a temporary AES 256 symmetric key that is used to encrypt the actual key material.
RSA 4096 OAEP SHA512 with AES 256 Key Wrapping: This will use a 4096 bit RSA wrapping key with Optimal Asymmetric Encryption Padding (OAEP) using a SHA512 digest to encrypt a temporary AES 256 symmetric key that is used to encrypt the actual key material.
What is this?
This section is copied from the STACKIT docs automatically, several times a day. It cannot be changed here. Changes belong in the STACKIT docs.
Limitations & Constraints
Section titled “Limitations & Constraints”- No Export of Generated Keys: Keys created inside the KMS cannot be exported outside the security boundary.
- Explicit Version Targeting: Key API requests must target explicit version numbers rather than auto-resolving aliases.
Asset historyActive 2 of the last 12 weeksTMUpdatedNo updates · 1 bar = 1 week i
- ?Name not public?Name not publicThe Cloud Framework team knows who this is. The name is not shown on the site.