By default, keys in a Key Management Service (KMS) instance are accessible for cryptographic operations only from a VPC. To access keys over the public network, you must enable public network access in the console. You can then call OpenAPI operations to perform cryptographic operations. This topic describes how to enable public network access.
Precautions
-
Regardless of the Queries Per Second (QPS) that you select when you purchase a KMS instance, the QPS for cryptographic operations over the public network is capped at 1,000. For more information, see Performance metrics. If your application has high performance requirements, use VPC network access.
-
By default, credentials in a KMS instance are accessible over the public network and from a VPC. If you access credentials only from the internal network, you do not need to enable public network access.
-
Public network access can be enabled only in the console, not by calling OpenAPI operations.
-
In a multi-account scenario where a KMS instance is shared, only the instance owner can enable public network access.
-
A local development environment cannot connect to the internal endpoint (VPC endpoint) of a KMS instance directly. If you switch from public network access to the internal endpoint to perform cryptographic operations from a local development environment, first establish network connectivity between your local environment and the VPC that hosts the instance. For example, you can use Cloud Enterprise Network (CEN) or VPN Gateway. Otherwise, connections to the internal endpoint fail or time out.
Enable public network access
Log on to the Key Management Service console. In the top navigation bar, select a region. In the left-side navigation pane, choose .
-
In the instance list, click the ID of the target instance. On the details page, turn on the Public Network Access switch in the RD Multi-Account section.
NoteIf a KMS instance is shared among multiple Alibaba Cloud accounts, you can set public network access permissions for each account.
-
On the Basic Information tab of the instance details page, find the Public Endpoint. The endpoint is displayed after you enable public network access and has a format similar to
kms.cn-hangzhou.aliyuncs.com.
What to do next
Use an Alibaba Cloud software development kit (SDK) to perform cryptographic operations over the public network. For more information, see Alibaba Cloud SDKs.
FAQ
If you have not configured an application access point (AAP), how do you access a KMS instance over a VPC endpoint and configure the certificate?
Scenarios: You access keys through the internal dedicated gateway of a KMS instance and have not configured an application access point (AAP). In this case, you must configure certificate trust on your own before you can perform cryptographic operations.
-
Log on to the Key Management Service console and go to the details page of the target instance. On the Basic Information tab, find Instance CA Certificate and click Download to download the certificate file. The file name uses the format
PrivateKmsCA_{InstanceID}.pem, where{InstanceID}is the instance ID of your KMS instance. -
Open the downloaded certificate file and copy its full content, including the header line
-----BEGIN CERTIFICATE-----and the footer line-----END CERTIFICATE-----. Pass the content as a string to the CA certificate trust configuration item of the Alibaba Cloud software development kit (SDK). This way, the SDK trusts the TLS certificate of the VPC endpoint of the KMS instance. -
Set the endpoint to the VPC Endpoint to Access Instance of the instance, which you can view on the Basic Information tab of the instance details page. This endpoint differs from the public endpoint described earlier in this topic, whose format is similar to
kms.cn-hangzhou.aliyuncs.com.
Do not disable certificate verification in a production environment. Disabling certificate verification introduces security risks. Always establish trust by configuring the instance CA certificate as described above.