I searched each of KMS and cloudHSM and I found same link that dll4835 said.
Q: Can I bring my own keys to AWS KMS?
Yes. You can import a copy of your key from your own key management infrastructure to AWS KMS and use it with any integrated AWS service or from within your own applications. You cannot import asymmetric CMKs into AWS KMS.
https://docs.aws.amazon.com/organizations/latest/userguide/orgs_introduction.html
this question is so needed narrow knowledge. as above said, KMS can import key except asymmetric CMKs.
When you use an HSM from AWS CloudHSM, you can perform a variety of cryptographic tasks:
Generate, store, import, export, and manage cryptographic keys, including symmetric keys and asymmetric key pairs.
https://docs.aws.amazon.com/crypto/latest/userguide/awscryp-service-hsm.html
you can import asymmetric CMKs by using CloudHSM.
So the answer is B.
There seems to be conflicting information. The FAQ's does indeed state the KMS does not support Asymmetric keys, but this link says that KMS now does.
https://aws.amazon.com/about-aws/whats-new/2019/11/aws-key-management-service-supports-asymmetric-keys/
Your link says that it supports creating asymmetric keys, but KMS still does not allow for IMPORTING asymmetric keys. https://aws.amazon.com/kms/features/
AWS CloudHSM is a service that provides hardware security modules in the AWS Cloud. It allows you to generate, store, and manage cryptographic keys securely and perform cryptographic operations in a dedicated hardware device. CloudHSM is designed to offer high-security key storage and cryptographic operations, making it suitable for applications with stringent security and compliance requirements.
B seems to be the answer here.
Q: Can I bring my own keys to AWS KMS?
Yes. You can import a copy of your key from your own key management infrastructure to AWS KMS and use it with any integrated AWS service or from within your own applications. You cannot import asymmetric KMS keys into AWS KMS.
https://aws.amazon.com/kms/faqs/
CloudHSM
Not KMS because
Imported key material is supported only for symmetric CMKs in AWS KMS key stores. It is not supported on asymmetric CMKs or CMKs in custom key stores.
https://docs.aws.amazon.com/kms/latest/developerguide/importing-keys.html
This is a confusing question. From the link provied found this quote.
"CloudHSM offers HSMs that are under your control, in your virtual private cloud (VPC). You can spin up an HSM device, create your key material, export it, import it into AWS KMS for use, "
I agree with jaribu said. the link says create and use asymmetric CMKs only. there is no information how can import asymmetric CMKs or not. this question is asking about to migrate asymmetric CMKs not to create and use.
With KMS you can do the following: Create keys; view ; edit; tag; enable and disable; download. But you can not import your keys. In CloudHSM you can do so.
I didn't know it was now supported. Thanks for raising it.
Curious which one should be used then between CloudHSM and KMS, since they don't mention single/multi tenancy?
Isn't CloudHSM a more suitable answer? KMS has traditionally only supported symmetric keys - and only began supporting asymmetric ones at the end of 2019.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
proxyolism
Highly Voted 2 years, 7 months agojoe_smoe
2 years, 6 months agotifoz
2 years, 7 months agosrle
2 years, 6 months agogilbertlelancelo
2 years, 7 months agogilbertlelancelo
2 years, 7 months agodll4835
Highly Voted 2 years, 7 months agoAWS1212
2 years, 7 months agoboboloboli
2 years, 6 months agoHuy
2 years, 6 months agoHuy
2 years, 6 months agoalbert_kuo
Most Recent 9 months, 2 weeks ago69657
2 years, 3 months agosaki0915
2 years, 6 months agoabhishek_m_86
2 years, 6 months agobillcayman
2 years, 6 months agoBKhan
2 years, 6 months agojackdryan
2 years, 6 months agoPartlyCloudy
2 years, 6 months agoJimmy5
2 years, 7 months agorewiga
2 years, 7 months agosuba1234
2 years, 7 months agoAWS_Noob
2 years, 7 months agonicat
2 years, 7 months agoproxyolism
2 years, 7 months agojaribu
2 years, 7 months agoGolddust
2 years, 7 months agoAWSvad
2 years, 7 months ago