Solved

Need help to correct Azure PowerShell stamens. Create Azure Vault and Set Keys...

Posted on 2016-08-29
6
26 Views
Last Modified: 2016-10-18
Hi, Please help to crate and configure Azure Key with PowerShell, I have my own certificate, and CA (Certificate Authority) should be able revoke cert. in case of security emergency...

New-AzureRmKeyVault –VaultName "MainVault" –ResourceGroupName "DevResources" –Location "West US"  ?????
// How to finish statement?
                  –Sku "Premium"
//                  OR
                  -EnabledForDiskEncryption
//                  ???


Add-AzureKeyVaultKey –VaultName “MainVault” –Name “MyString1”    ????
// How to finish statement? HSM and Import Certificate or Software?
                  -Destination HSM -KeyFilePath ‘C:\MyCertificates\MyCertKey.pfx’ -KeyFilePassword ‘********’
//                  OR
                  -Destination Software –KeyOps @(‘decrypt’,’sign’)

Set-AzureKeyVaultSecret –VaultName “VT” –Name ‘NameString’ –SecretValue ‘***SomePaword***’

Greatly appreciated your help.
0
Comment
Question by:Sergey Gimplin
  • 3
6 Comments
 
LVL 5

Accepted Solution

by:
Zachariah Browning earned 500 total points (awarded by participants)
ID: 41780896
New-AzureRmKeyVault –VaultName "MainVault" –ResourceGroupName "DevResources" –Location "West US" -Sku "Premium"

           -You would add -Sku "Premium" if you want a  premium key vault which enables HSM protected keys $1 per key per month + standard transfer pricing. other prices are the same, so if you plan to generate and transfer your own HSM protected keys- then use this option.  (seems like you want to)
          -EnabledForDiskEncryption is an option to allow azure disk encryption service to get and unwrap/use keys from the vault and there are other options set out and described on the MSDN page for this powershell command that could be useful depending on your circumstances.

for adding a key to your vault the tutorial below has a great explanation of how to do this, especially with a predefined .PFX file. You have it down pretty well. as recopied immediately below, just make sure your keyfilepassword is plain text, or do as they did in the tutorial forcing secure string plain text.

 Add-AzureKeyVaultKey -VaultName "MainVault" -Name "MyString1" -KeyFilePath  ‘C:\MyCertificates\MyCertKey.pfx’  -KeyFilePassword ‘********’  

Here is a very good tutorial that should answer any other questions that you may have.
1
 
LVL 5

Expert Comment

by:Zachariah Browning
ID: 41840604
I feel that sufficient information was provided to help correct the powershell statement AND explain why and what each piece did. The user simply took the answer and gave no further input.
0
 
LVL 5

Expert Comment

by:Zachariah Browning
ID: 41847919
Selecting the appropriate answer for the answer of the stated question.
0

Featured Post

Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The following article is intended as a guide to using PowerShell as a more versatile and reliable form of application detection in SCCM.
The Nano Server Image Builder helps you create a custom Nano Server image and bootable USB media with the aid of a graphical interface. Based on the inputs you provide, it generates images for deployment and creates reusable PowerShell scripts that …
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …
Exchange organizations may use the Journaling Agent of the Transport Service to archive messages going through Exchange. However, if the Transport Service is integrated with some email content management application (such as an antispam), the admini…

749 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question