Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Need help to correct Azure PowerShell stamens. Create Azure Vault and Set Keys...

Posted on 2016-08-29
6
Medium Priority
?
45 Views
Last Modified: 2016-10-18
Hi, Please help to crate and configure Azure Key with PowerShell, I have my own certificate, and CA (Certificate Authority) should be able revoke cert. in case of security emergency...

New-AzureRmKeyVault –VaultName "MainVault" –ResourceGroupName "DevResources" –Location "West US"  ?????
// How to finish statement?
                  –Sku "Premium"
//                  OR
                  -EnabledForDiskEncryption
//                  ???


Add-AzureKeyVaultKey –VaultName “MainVault” –Name “MyString1”    ????
// How to finish statement? HSM and Import Certificate or Software?
                  -Destination HSM -KeyFilePath ‘C:\MyCertificates\MyCertKey.pfx’ -KeyFilePassword ‘********’
//                  OR
                  -Destination Software –KeyOps @(‘decrypt’,’sign’)

Set-AzureKeyVaultSecret –VaultName “VT” –Name ‘NameString’ –SecretValue ‘***SomePaword***’

Greatly appreciated your help.
0
Comment
Question by:Sergey Gimplin
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
6 Comments
 
LVL 5

Accepted Solution

by:
Zachariah Browning earned 2000 total points (awarded by participants)
ID: 41780896
New-AzureRmKeyVault –VaultName "MainVault" –ResourceGroupName "DevResources" –Location "West US" -Sku "Premium"

           -You would add -Sku "Premium" if you want a  premium key vault which enables HSM protected keys $1 per key per month + standard transfer pricing. other prices are the same, so if you plan to generate and transfer your own HSM protected keys- then use this option.  (seems like you want to)
          -EnabledForDiskEncryption is an option to allow azure disk encryption service to get and unwrap/use keys from the vault and there are other options set out and described on the MSDN page for this powershell command that could be useful depending on your circumstances.

for adding a key to your vault the tutorial below has a great explanation of how to do this, especially with a predefined .PFX file. You have it down pretty well. as recopied immediately below, just make sure your keyfilepassword is plain text, or do as they did in the tutorial forcing secure string plain text.

 Add-AzureKeyVaultKey -VaultName "MainVault" -Name "MyString1" -KeyFilePath  ‘C:\MyCertificates\MyCertKey.pfx’  -KeyFilePassword ‘********’  

Here is a very good tutorial that should answer any other questions that you may have.
1
 
LVL 5

Expert Comment

by:Zachariah Browning
ID: 41840604
I feel that sufficient information was provided to help correct the powershell statement AND explain why and what each piece did. The user simply took the answer and gave no further input.
0
 
LVL 5

Expert Comment

by:Zachariah Browning
ID: 41847919
Selecting the appropriate answer for the answer of the stated question.
0

Featured Post

Learn how to optimize MySQL for your business need

With the increasing importance of apps & networks in both business & personal interconnections, perfor. has become one of the key metrics of successful communication. This ebook is a hands-on business-case-driven guide to understanding MySQL query parameter tuning & database perf

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

My attempt to use PowerShell and other great resources found online to simplify the deployment of Office 365 ProPlus client components to any workstation that needs it, regardless of existing Office components that may be needing attention.
Auditing domain password hashes is a commonly overlooked but critical requirement to ensuring secure passwords practices are followed. Methods exist to extract hashes directly for a live domain however this article describes a process to extract u…
Exchange organizations may use the Journaling Agent of the Transport Service to archive messages going through Exchange. However, if the Transport Service is integrated with some email content management application (such as an antispam), the admini…
In response to a need for security and privacy, and to continue fostering an environment members can turn to for support, solutions, and education, Experts Exchange has created anonymous question capabilities. This new feature is available to our Pr…

715 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question