This section describes how to create a custom key on the KMS console.
When you create a key as an IAM user, you have granted the KMS CMKFullAccess or higher permissions to the IAM user. For details, see Creating a User and Authorizing the User the Permission to Access DEW.
in the upper left corner of the management console and select a region or project.
on the left and choose .Figure 1 Creating a key

Parameter | Description |
|---|---|
Alias | Name of the key you are creating. NOTE:
|
Key Algorithm | Select a key algorithm. |
Usage | Key usage. The value cannot be changed after the key is created. The value can be SIGN_VERIFY, ENCRYPT_DECRYPT, or GENERATE_VERIFY_MAC.
NOTE: The key usage can only be configured during key creation and cannot be modified afterwards. |
Enterprise Project | This parameter is provided for enterprise users. If you are an enterprise user and have created an enterprise project, select the required enterprise project from the drop-down list. The default project is default. If there are no Enterprise Management options displayed, you do not need to configure it. |
Description | Add description for a custom key as needed. You can enter up to 255 characters. |
Tag | Add tags to the custom key as needed, and enter the tag key and tag value. NOTE:
|