Files
doc-exports/docs/kms/umn/dew_01_0044.html
qinweiwei 3e4721c813 KMS UMN 20251111 version
Reviewed-by: Rogal, Marcel <mrogal@noreply.gitea.eco.tsi-dev.otc-service.com>
Co-authored-by: qinweiwei <qinweiwei@huawei.com>
Co-committed-by: qinweiwei <qinweiwei@huawei.com>
2026-01-19 09:05:54 +00:00

57 lines
4.5 KiB
HTML

<a name="dew_01_0044"></a><a name="dew_01_0044"></a>
<h1 class="topictitle1">What Is a Customer Master Key?</h1>
<div id="body8662426"><p id="dew_01_0044__en-us_topic_0035099206_p8060118">A Customer Master Key (CMK) is a Key Encryption Key (KEK) created by a user on KMS. It is used to encrypt and protect DEKs. One CMK can be used to encrypt one or more DEKs.</p>
<div class="p" id="dew_01_0044__p127610196502">CMKs are categorized into custom keys and default keys.<ul id="dew_01_0044__ul1875994575019"><li id="dew_01_0044__li147591145115017">Custom keys<p id="dew_01_0044__p988775013500"><a name="dew_01_0044__li147591145115017"></a><a name="li147591145115017"></a>Keys created or imported by users on the KMS console.</p>
</li><li id="dew_01_0044__li1875934520501">Default keys<p id="dew_01_0044__p20959752125018"><a name="dew_01_0044__li1875934520501"></a><a name="li1875934520501"></a>When a user uses KMS for encryption in a cloud service for the first time, the cloud service automatically creates a key with the alias suffix <strong id="dew_01_0044__b195113158392">/default</strong>.</p>
<p id="dew_01_0044__p37369926114355">You can use the management console to query but cannot disable or schedule the deletion of Default Master Keys.</p>
<div class="tablenoborder"><table cellpadding="4" cellspacing="0" summary="" id="dew_01_0044__table42686454104828" frame="border" border="1" rules="all"><caption><b>Table 1 </b>Default master keys</caption><thead align="left"><tr id="dew_01_0044__dew_01_0045_row59355676104828"><th align="left" class="cellrowborder" valign="top" width="26.5%" id="mcps1.3.2.1.2.3.2.3.1.1"><p id="dew_01_0044__dew_01_0045_p58543282104828"><strong id="dew_01_0044__dew_01_0045_b842352706114440_1">Alias</strong></p>
</th>
<th align="left" class="cellrowborder" valign="top" width="73.5%" id="mcps1.3.2.1.2.3.2.3.1.2"><p id="dew_01_0044__dew_01_0045_p66197698104828"><strong id="dew_01_0044__dew_01_0045_b842352706114445_1">Cloud Service</strong></p>
</th>
</tr>
</thead>
<tbody><tr id="dew_01_0044__dew_01_0045_row53124038104828"><td class="cellrowborder" valign="top" width="26.5%" headers="mcps1.3.2.1.2.3.2.3.1.1 "><p id="dew_01_0044__dew_01_0045_p22934402104828">obs/default</p>
</td>
<td class="cellrowborder" valign="top" width="73.5%" headers="mcps1.3.2.1.2.3.2.3.1.2 "><p id="dew_01_0044__dew_01_0045_p66818200104828">Object Storage Service (OBS)</p>
</td>
</tr>
<tr id="dew_01_0044__dew_01_0045_row41239781104828"><td class="cellrowborder" valign="top" width="26.5%" headers="mcps1.3.2.1.2.3.2.3.1.1 "><p id="dew_01_0044__dew_01_0045_p41471516104828">evs/default</p>
</td>
<td class="cellrowborder" valign="top" width="73.5%" headers="mcps1.3.2.1.2.3.2.3.1.2 "><p id="dew_01_0044__dew_01_0045_p65102400104828">Elastic Volume Service (EVS)</p>
</td>
</tr>
<tr id="dew_01_0044__dew_01_0045_row2311958917544"><td class="cellrowborder" valign="top" width="26.5%" headers="mcps1.3.2.1.2.3.2.3.1.1 "><p id="dew_01_0044__dew_01_0045_p6074740317544">ims/default</p>
</td>
<td class="cellrowborder" valign="top" width="73.5%" headers="mcps1.3.2.1.2.3.2.3.1.2 "><p id="dew_01_0044__dew_01_0045_p2159264717544">Image Management Service (IMS)</p>
</td>
</tr>
<tr id="dew_01_0044__dew_01_0045_row20537184217141"><td class="cellrowborder" valign="top" width="26.5%" headers="mcps1.3.2.1.2.3.2.3.1.1 "><p id="dew_01_0044__dew_01_0045_p165084781416">sfs/default</p>
</td>
<td class="cellrowborder" valign="top" width="73.5%" headers="mcps1.3.2.1.2.3.2.3.1.2 "><p id="dew_01_0044__dew_01_0045_p106501847101420">Scalable File Service (SFS)</p>
</td>
</tr>
<tr id="dew_01_0044__dew_01_0045_row161641750103819"><td class="cellrowborder" valign="top" width="26.5%" headers="mcps1.3.2.1.2.3.2.3.1.1 "><p id="dew_01_0044__dew_01_0045_p11644505385">rds/default</p>
</td>
<td class="cellrowborder" valign="top" width="73.5%" headers="mcps1.3.2.1.2.3.2.3.1.2 "><p id="dew_01_0044__dew_01_0045_p316415507387">Relational Database Service (RDS)</p>
</td>
</tr>
<tr id="dew_01_0044__dew_01_0045_row84561753914"><td class="cellrowborder" valign="top" width="26.5%" headers="mcps1.3.2.1.2.3.2.3.1.1 "><p id="dew_01_0044__dew_01_0045_p845647193918">dds/default</p>
</td>
<td class="cellrowborder" valign="top" width="73.5%" headers="mcps1.3.2.1.2.3.2.3.1.2 "><p id="dew_01_0044__dew_01_0045_p1445710793910">Document Database Service (DDS)</p>
</td>
</tr>
</tbody>
</table>
</div>
</li></ul>
</div>
</div>
<div>
<div class="familylinks">
<div class="parentlink"><strong>Parent topic:</strong> <a href="dew_01_0092.html">FAQs</a></div>
</div>
</div>