Endpoint Standard: Does the AWS data forwarder support customer-managed KMS keys?
book
Article ID: 289227
calendar_today
Updated On:
Products
Carbon Black Cloud Endpoint Standard (formerly Cb Defense)Carbon Black Cloud Enterprise EDR (formerly Cb Threathunter)
Issue/Introduction
Does the AWS data forwarder support customer-managed KMS keys?
Environment
Carbon Black Cloud Console: All Versions
Data Forwarder
Amazon Simple Storage Service (Amazon S3)
Resolution
Yes, using KMS encryption is an optional configuration that is supported: https://developer.carbonblack.com/reference/carbon-black-cloud/integrations/data-forwarder/quick-setup/#optional-setup-kms-encryption
Additional Information
KMS Bucket Keys are not specifically "required" but are "recommended". The configuration that was approved and added to the developer.carbonblack.com site was tested and validated with Bucket keys enabled.