Loading
Feature degradation | Gmail Email delivery failureRead More
Set Up and Maintain Your Salesforce Organization
Table of Contents
Select Filters

          No results
          No results
          Here are some search tips

          Check the spelling of your keywords.
          Use more general search terms.
          Select fewer filters to broaden your search.

          Search all of Salesforce Help
          Upload a BYOK Tenant Secret for Database Encryption

          Upload a BYOK Tenant Secret for Database Encryption

          For Database Encryption, you upload a tenant secret as your BYOK material. The Shield Key Management Service (KMS) uses your tenant secret to derive the keys used for encrypting and decrypting your transactional database data. This tenant secret is only used for Database Encryption.

          Required Editions

          Available in both Salesforce Classic (not available in all orgs) and Lightning Experience.
          Available in: Enterprise, Performance, and Unlimited Editions with the Salesforce Shield or Shield Platform Encryption licenses.
          Available for free in Developer Edition.
          User Permissions Needed
          To generate, destroy, export, import, upload, and configure key material: Manage Encryption Keys
          To view and edit Setup: View Setup and Configuration
          1. From Setup, in the Quick Find box, enter Platform Encryption, and then select Key Management.
            The Key Inventory and Management page loads.
          2. In the Key Management Table, select Database.
          3. Click Bring Your Own Key.
            If you’re prompted to generate a certificate, choose either Self-Signed or CA Signed. If you have already created certificates you can either select one of those or create a new one.
            Select Certificate Type for BYOK
            Note
            Note This certificate is used only to secure the upload of your key material.
          4. If you choose to create a new certificate, the Certificate and Key Management page appears.
            In the provided space, type a label, and then select Save.
            Generate Certificate
          5. On the Bring Your Own Database Encryption Key page, click Download Certificate and Token to download the files you need to prepare and upload your tenant secret.
          6. Use the certificate to prepare your key material for upload. See Wrap BYOK Key Material.
          7. After you have wrapped your key material, in the Upload Tenant Secret section, attach both the encrypted key material and the session_token.txt file associated with your certificate. Click Upload.
            Upload Tenant Secret for Database Encryption

            This tenant secret becomes the active tenant secret for Database Encryption.

            From here on, the Shield KMS uses your tenant secret as part of a derived key used to encrypt and decrypt your users’ search data.

           
          Loading
          Salesforce Help | Article