Solved

Need help to correct Azure PowerShell stamens. Create Azure Vault and Set Keys...

Posted on 2016-08-29
6
19 Views
Last Modified: 2016-10-18
Hi, Please help to crate and configure Azure Key with PowerShell, I have my own certificate, and CA (Certificate Authority) should be able revoke cert. in case of security emergency...

New-AzureRmKeyVault –VaultName "MainVault" –ResourceGroupName "DevResources" –Location "West US"  ?????
// How to finish statement?
                  –Sku "Premium"
//                  OR
                  -EnabledForDiskEncryption
//                  ???


Add-AzureKeyVaultKey –VaultName “MainVault” –Name “MyString1”    ????
// How to finish statement? HSM and Import Certificate or Software?
                  -Destination HSM -KeyFilePath ‘C:\MyCertificates\MyCertKey.pfx’ -KeyFilePassword ‘********’
//                  OR
                  -Destination Software –KeyOps @(‘decrypt’,’sign’)

Set-AzureKeyVaultSecret –VaultName “VT” –Name ‘NameString’ –SecretValue ‘***SomePaword***’

Greatly appreciated your help.
0
Comment
Question by:Sergey Gimplin
  • 3
6 Comments
 
LVL 5

Accepted Solution

by:
Zachariah Browning earned 500 total points (awarded by participants)
ID: 41780896
New-AzureRmKeyVault –VaultName "MainVault" –ResourceGroupName "DevResources" –Location "West US" -Sku "Premium"

           -You would add -Sku "Premium" if you want a  premium key vault which enables HSM protected keys $1 per key per month + standard transfer pricing. other prices are the same, so if you plan to generate and transfer your own HSM protected keys- then use this option.  (seems like you want to)
          -EnabledForDiskEncryption is an option to allow azure disk encryption service to get and unwrap/use keys from the vault and there are other options set out and described on the MSDN page for this powershell command that could be useful depending on your circumstances.

for adding a key to your vault the tutorial below has a great explanation of how to do this, especially with a predefined .PFX file. You have it down pretty well. as recopied immediately below, just make sure your keyfilepassword is plain text, or do as they did in the tutorial forcing secure string plain text.

 Add-AzureKeyVaultKey -VaultName "MainVault" -Name "MyString1" -KeyFilePath  ‘C:\MyCertificates\MyCertKey.pfx’  -KeyFilePassword ‘********’  

Here is a very good tutorial that should answer any other questions that you may have.
1
 
LVL 5

Expert Comment

by:Zachariah Browning
ID: 41840604
I feel that sufficient information was provided to help correct the powershell statement AND explain why and what each piece did. The user simply took the answer and gave no further input.
0
 
LVL 5

Expert Comment

by:Zachariah Browning
ID: 41847919
Selecting the appropriate answer for the answer of the stated question.
0

Featured Post

NAS Cloud Backup Strategies

This article explains backup scenarios when using network storage. We review the so-called “3-2-1 strategy” and summarize the methods you can use to send NAS data to the cloud

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Utilizing an array to gracefully append to a list of EmailAddresses
This script can help you clean up your user profile database by comparing profiles to Active Directory users in a particular OU, and removing the profiles that don't match.
Concerto provides fully managed cloud services and the expertise to provide an easy and reliable route to the cloud. Our best-in-class solutions help you address the toughest IT challenges, find new efficiencies and deliver the best application expe…
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …

930 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now