1.0 Introduction
This article describes how to integrate Fortanix-Data-Security-Manager (DSM) with AWS External Key Store (XKS) to protect the data in AWS using keys stored in Fortanix DSM that users can use to perform cryptographic operations.
When using Fortanix DSM as an external key store for AWS Key Management Service, AWS allows two ways of communication:
Public Endpoint Connectivity - AWS KMS connects to the external key store proxy (XKS proxy) over the internet using a public endpoint.
Using Amazon VPC endpoint service - AWS KMS connects to the XKS proxy by creating an interface endpoint to an Amazon VPC endpoint service. This method uses AWS PrivateLink, which enables AWS KMS to privately connect to your Amazon VPC and your XKS proxy without using the public internet.
This article describes how to successfully integrate Fortanix DSM as an external keystore for AWS KMS using the public endpoint connectivity method. You can follow the article – Fortanix DSM with AWS External Key Store (XKS) - Concepts and Data Security Manager with Amazon XKS Using Virtual Private Cloud using Amazon VPS Integration Guide for the Amazon VPC endpoint service method.
2.0 Prerequisites
Ensure the following:
Fortanix DSM version 4.9 and above: Fortanix introduced XKS support in DSM version 4.9 but requires the feature to be enabled through Fortanix Support. This feature became available by default starting with DSM version 4.16.
AWS Console
AES 256 key – For the initial implementation, only AES 256 keys are supported. This key is created in Fortanix DSM.
NOTE
The AES key can either be imported or created in Fortanix DSM.
3.0 Using Fortanix DSM with AWS XKS
With AWS XKS, administrators use Fortanix DSM to store cryptographic keys for encrypting and decrypting data in AWS. In this method, cryptographic operations are performed inside Fortanix DSM. This differs from the import-key (known as Bring Your Own Key, or BYOK) functionality, where the key material for a key in Fortanix DSM (external HSM) is imported into AWS KMS, optionally with an expiration period, and cryptographic operations occur within an AWS data center.
4.0 Configure Fortanix DSM
A Fortanix DSM service must be configured, and the URL must be accessible. To create a Fortanix DSM account and group, refer to the following sections:
4.1 Signing Up
To get started with the Fortanix DSM cloud service, you must register an account at <Your_DSM_Service_URL>. For example, https://amer.smartkey.io. On-premises customers use the KMS URL, and the SaaS customers can use the URLs as listed here based on the application region.
For more information on how to set up the Fortanix DSM, refer to Sign Up for Fortanix Data Security Manager SaaS.
4.2 Creating an Account
Access <Your_DSM_Service_URL> in a web browser and enter your credentials to log in to Fortanix DSM.
.png?sv=2026-02-06&spr=https&st=2026-08-31T18%3A18%3A49Z&se=2026-08-31T18%3A40%3A49Z&sr=c&sp=r&sig=54ZTGVV5%2BzOmkZ%2BoFSBav45qdpW2qP3sTcez57pGqoY%3D)
Figure 1: Logging in
For more information on how to set up an account in Fortanix DSM, refer to Getting Started with Fortanix Data Security Manager - UI.
4.3 Creating a Group
Perform the following steps to create a group in the Fortanix DSM:
In the DSM left navigation panel, click the Groups menu item, and then click ADD GROUP to create a new group.
.png?sv=2026-02-06&spr=https&st=2026-08-31T18%3A18%3A49Z&se=2026-08-31T18%3A40%3A49Z&sr=c&sp=r&sig=54ZTGVV5%2BzOmkZ%2BoFSBav45qdpW2qP3sTcez57pGqoY%3D)
Figure 2: Add groups
On the Adding new group page:
Title: Enter a name for your group.
Description (optional): Enter a short description of the group.
Click SAVE to create the new group.
For more information about groups, refer to Definitions.
TIP
It is recommended to configure a Key undo policy for groups for the cryptographic keys used by the application before creating or using the keys. Without a configured Key undo policy, key deletion is permanent and the deleted key cannot be recovered. Deleting an encryption key may result in permanent loss of access to the protected data and service disruption for applications that depend on the deleted key. For detailed steps, refer to Key Undo Policy.
4.4 Creating or Importing an AES Key
NOTE
The AES security object created in this section serves as the AWS XKS Root Key. AWS KMS uses this key through Fortanix DSM to encrypt and decrypt AWS-generated data keys.
Perform the following steps to generate an AES key in the Fortanix DSM:
In the DSM left navigation panel, click the Security Objects menu item, and then click ADD SECURITY OBJECT to create a new security object.
.png?sv=2026-02-06&spr=https&st=2026-08-31T18%3A18%3A49Z&se=2026-08-31T18%3A40%3A49Z&sr=c&sp=r&sig=54ZTGVV5%2BzOmkZ%2BoFSBav45qdpW2qP3sTcez57pGqoY%3D)
Figure 3: Adding security object
On the Add new Security Object page:
Security Object name: Enter the name for your security object.
Group: Select the group as created in Section 4.3: Creating a Group.
Select GENERATE.
In the Choose a type section, select the AES key type.
In the Key Size section, select the size of the key in bits.
In the Key operations permitted section, select the required operations to define the actions that can be performed with the cryptographic keys, such as encryption, decryption, signing, and verifying.
NOTE
Ensure that the new key has Encrypt and Decrypt key operations allowed.
Click GENERATE to create the new security object.
For more information about security objects, refer to Definitions.
You can also import an AES encryption key. For more information on how to import a key, refer to Fortanix Data Security Manager Key Lifecycle Management.
4.5 Copying the UUID of the AES Key
Perform the following steps to copy the security object UUID from the Fortanix DSM:
In the DSM left navigation panel, click the Security Objects menu item, and then click the security object created in Section 4.4: Creating or Importing an AES Key to go to the detailed view of the security object.
From the top of the security object’s page, click the COPY ID drop down menu and then select COPY UUID to copy it to use later.
4.6 Copying the External Key ID
To support AWS XKS Root Key Rotation, configure the External Key ID in AWS KMS using the Fortanix DSM security object name instead of the security object UUID. When the security object is referenced by name, DSM can continue to locate the active key after it is rotated. XKS Root Keys referenced by security object name can be rotated manually or using a key rotation policy.
Perform the following steps to obtain the security object identifier to use as the External Key ID in AWS KMS:
In the DSM left navigation panel, click Security Objects, and then select the security object created in Section 4.4: Creating or Importing an AES Key.
On the security object details page, click the COPY ID drop down menu.
Select COPY XKS KEY ID to copy the security object name to use as the External Key ID when creating the AWS KMS key.
NOTE
XKS Root Key rotation is supported only when the External Key ID references the Fortanix DSM security object by name. If the security object UUID is used as the External Key ID, Fortanix DSM cannot automatically use the rotated key, and XKS Root Key rotation is not supported.
The XKS Key ID format
.{name}is supported when creating AWS KMS external keys using the AWS CLI. The AWS Management Console currently does not accept XKS Key IDs that begin with a period(.). To ensure compatibility with both the AWS CLI and the AWS Management Console, use the Base64-encoded XKS Key ID formatZ{name_b64}.
4.7 Creating an Application
Perform the following steps to create an application (app) in the Fortanix DSM:
In the DSM left navigation panel, click the Apps menu item, and then click ADD APP to create a new app.
.png?sv=2026-02-06&spr=https&st=2026-08-31T18%3A18%3A49Z&se=2026-08-31T18%3A40%3A49Z&sr=c&sp=r&sig=54ZTGVV5%2BzOmkZ%2BoFSBav45qdpW2qP3sTcez57pGqoY%3D)
Figure 4: Add application
On the Adding new app page:
App name: Enter the name for your application.
ADD DESCRIPTION (optional): Enter a short description of the application.
Authentication method: Select AWS XKS as the authentication method from the drop down menu. For more information on these authentication methods, refer to Authentication.
Assigning the new app to groups: Select the group created in Section 4.3: Creating a Group from the list.
Click SAVE to add the new application.
For more information about applications, refer to Definitions.
4.8 Updating the Authentication Method
You can also change the authentication method for an existing app to AWS XKS from the detailed view of an app.
WARNING
Updating an authentication method causes the services relying on the app to stop working.
Perform the following steps to change the authentication method:
Go to the detailed view of the app created in Section 4.7: Creating an Application and then click Change authentication method and select AWS XKS to change the authentication method to AWS XKS.
Click SAVE.
4.9 Copying the App Configuration File
Perform the following steps to copy the app configuration file from the Fortanix DSM to configure DSM as an XKS in AWS:
In the DSM left navigation panel, click the Apps menu item, and then click the app created in Section 4.7: Creating an Application to go to the detailed view of the app.
In the INFO tab and the AWS XKS section, click VIEW INSTRUCTIONS.
In the AWS XKS modal window, click COPY CONFIG FILE to copy all the configuration details at once to the clipboard in JSON format or copy the URI and the configuration info individually and make a note of it.
The following are the configuration values:
Path prefix: A fixed path containing the Fortanix DSM app UUID.
Access key ID and Secret access key: The access key and secret access key are used by AWS to access Fortanix DSM.

Figure 5: Copy the AWS XKS app configuration
NOTE
"amer.smartkey.io" opens DSM SaaS for the AMER region. DSM SaaS supports multiple regions, as listed here.
5.0 Configure DSM as an XKS with AWS
Perform the following steps:
Go to the AWS Console.
Click Services → Key Management Service.

Figure 6: Select AWS KMS
From the left menu, select Custom key stores → External key stores.
On the External key stores page, click Create external key store.

Figure 7: Create an external key store
In the Create external key store form:
Key store name: Enter a name for your key store. For example, XKS Test.

Figure 8: Create XKS
In the Proxy Connectivity section:
Select the Public endpoint to communicate with the Fortanix DSM proxy.
In the Proxy URI endpoint field, enter the URI that you copied in Step 2. For example,
https://<fortanix_dsm_url>.
Figure 9: Create XKS
In the Proxy configuration section:
Paste the individual configuration values that you copied in Step 2 in the Proxy URI path prefix, Access key ID, and Secret access key fields, respectively OR
Click Upload configuration file and paste the JSON configuration details that you copied in Step 2.

Figure 10: Upload configuration file
If you selected option (ii) above, then paste the JSON Configuration in the text box and click Use this proxy configuration to save the configuration.

Figure 11: Proxy configuration
Click Create external key store to complete the XKS creation process.

Figure 12: Create XKS
Click the Connect key store to connect the XKS with Fortanix DSM so that you can start creating the keys in this key store.

Figure 13: Connect keystore
6.0 Create Keys in the External Key Store
After the connection between AWS XKS and Fortanix DSM is successful, you can start creating keys in this key store using the following steps:
Click Create a KMS key in this key store to create a key.

Figure 14: Create a key
In the External key ID section, enter the UUID of the AES 256 key as copied in Section 4.5: Copying the UUID of the AES Key.
Select the check box to Confirm use of external key store.
Click Next.

Figure 15: External key ID
In the Add labels page, enter the key Alias.
Click Next.

Figure 16: Add alias
Next, select the key administrators who can administer this key using the KMS API and click Next.

Figure 17: Key administrators
Select the users who will use the key for cryptographic operations and click Next.

Figure 18: Key usage permissions
Review the updates and click Finish.
The AWS KMS key is now successfully created in the XKS.

Figure 19: Key created in XKS
7.0 Rotate AWS XKS Root Keys
Fortanix DSM supports rotating AWS XKS Root Keys manually or automatically using a key rotation policy. Rotating an XKS Root Key replaces the key used for new encryption operations while allowing previously encrypted data to remain decryptable.
NOTE
XKS Root Key rotation is supported only when the External Key ID configured in AWS KMS references the Fortanix DSM security object by name. XKS Root Key rotation is not supported when the External Key ID references the security object by UUID.
After rotation, the previous XKS Root Key can be deactivated but must not be disabled because it may still be required to decrypt data that was encrypted before the rotation.
7.1 Manually Rotate an XKS Root Key
Perform the following steps to manually rotate an AWS XKS Root Key:
In the DSM left navigation panel, click Security Objects, and then select the XKS Root Key that you want to rotate.
In the detailed view of the security object, click ROTATE KEY.
In the Key Rotation window, select either of the following options:
Generate a new key: Generates a new key with the configured key attributes. The original key is automatically renamed, and the newly generated key inherits the original key name and becomes the active XKS Root key
Rotate to an existing key: Select an existing key to replace the active XKS Root Key. The current XKS Root Key is automatically renamed, and the selected key inherits its name.
To deactivate the original key after rotation, select Deactivate original key after rotation.
Click ROTATE KEY.
After the key is successfully rotated, Fortanix DSM automatically uses the new XKS Root Key for all subsequent encryption operations. The previous key remains available for decrypting data encrypted before the rotation.
7.2 Configuring a Key Rotation Policy
You can configure a key rotation policy to automatically rotate the AWS XKS Root Key at scheduled intervals.
Perform the following steps to configure a key rotation policy:
In the DSM left navigation panel, click Security Objects, and then select the XKS Root Key.
In the key detailed view, click the KEY ROTATION tab, and then click ADD POLICY.
In the Key rotation policy section, specify the rotation frequency, start date, and time.
Optionally, select the Deactivate original key after rotation check box to deactivate the original key after rotation.
Optionally, select the Enable key rotation for copied keys in CDC groups check box to rotate copies of the XKS Root Key that are part of Cloud Data Control (CDC) groups.
Click SAVE POLICY to save the policy.
DSM automatically rotates the XKS Root Key according to the configured schedule while continuing to support decryption of data encrypted before each rotation.
For more information on the key rotation policy, refer to Fortanix Data Security Manager Key Lifecycle Management.