Solved

Need help to correct Azure PowerShell stamens. Create Azure Vault and Set Keys...

Posted on 2016-08-29
6
22 Views
Last Modified: 2016-10-18
Hi, Please help to crate and configure Azure Key with PowerShell, I have my own certificate, and CA (Certificate Authority) should be able revoke cert. in case of security emergency...

New-AzureRmKeyVault –VaultName "MainVault" –ResourceGroupName "DevResources" –Location "West US"  ?????
// How to finish statement?
                  –Sku "Premium"
//                  OR
                  -EnabledForDiskEncryption
//                  ???


Add-AzureKeyVaultKey –VaultName “MainVault” –Name “MyString1”    ????
// How to finish statement? HSM and Import Certificate or Software?
                  -Destination HSM -KeyFilePath ‘C:\MyCertificates\MyCertKey.pfx’ -KeyFilePassword ‘********’
//                  OR
                  -Destination Software –KeyOps @(‘decrypt’,’sign’)

Set-AzureKeyVaultSecret –VaultName “VT” –Name ‘NameString’ –SecretValue ‘***SomePaword***’

Greatly appreciated your help.
0
Comment
Question by:Sergey Gimplin
  • 3
6 Comments
 
LVL 5

Accepted Solution

by:
Zachariah Browning earned 500 total points (awarded by participants)
ID: 41780896
New-AzureRmKeyVault –VaultName "MainVault" –ResourceGroupName "DevResources" –Location "West US" -Sku "Premium"

           -You would add -Sku "Premium" if you want a  premium key vault which enables HSM protected keys $1 per key per month + standard transfer pricing. other prices are the same, so if you plan to generate and transfer your own HSM protected keys- then use this option.  (seems like you want to)
          -EnabledForDiskEncryption is an option to allow azure disk encryption service to get and unwrap/use keys from the vault and there are other options set out and described on the MSDN page for this powershell command that could be useful depending on your circumstances.

for adding a key to your vault the tutorial below has a great explanation of how to do this, especially with a predefined .PFX file. You have it down pretty well. as recopied immediately below, just make sure your keyfilepassword is plain text, or do as they did in the tutorial forcing secure string plain text.

 Add-AzureKeyVaultKey -VaultName "MainVault" -Name "MyString1" -KeyFilePath  ‘C:\MyCertificates\MyCertKey.pfx’  -KeyFilePassword ‘********’  

Here is a very good tutorial that should answer any other questions that you may have.
1
 
LVL 5

Expert Comment

by:Zachariah Browning
ID: 41840604
I feel that sufficient information was provided to help correct the powershell statement AND explain why and what each piece did. The user simply took the answer and gave no further input.
0
 
LVL 5

Expert Comment

by:Zachariah Browning
ID: 41847919
Selecting the appropriate answer for the answer of the stated question.
0

Featured Post

Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Healthcare organizations in the United States must adhere to the guidance of both the HIPAA (Health Insurance Portability and Accountability Act) and HITECH (Health Information Technology for Economic and Clinical Health Act) for securing and protec…
This article explains how to prepare an HTML email signature template file containing dynamic placeholders for users' Azure AD data. Furthermore, it explains how to use this file to remotely set up a department-wide email signature policy in Office …
Two types of users will appreciate AOMEI Backupper Pro: 1 - Those with PCIe drives (and haven't found cloning software that works on them). 2 - Those who want a fast clone of their boot drive (no re-boots needed) and it can clone your drive wh…
Finds all prime numbers in a range requested and places them in a public primes() array. I've demostrated a template size of 30 (2 * 3 * 5) but larger templates can be built such 210  (2 * 3 * 5 * 7) or 2310  (2 * 3 * 5 * 7 * 11). The larger templa…

789 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question