Endpoint Standard: Does the AWS data forwarder support customer-managed KMS keys?
search cancel

Endpoint Standard: Does the AWS data forwarder support customer-managed KMS keys?

book

Article ID: 289227

calendar_today

Updated On:

Products

Carbon Black Cloud Endpoint Standard (formerly Cb Defense) Carbon Black Cloud Enterprise EDR (formerly Cb Threathunter)

Issue/Introduction

Does the AWS data forwarder support customer-managed KMS keys?

Environment

  • Carbon Black Cloud Console: All Versions
  • Data Forwarder
  • Amazon Simple Storage Service (Amazon S3)

Resolution

Yes, using KMS encryption is an optional configuration that is supported: https://developer.carbonblack.com/reference/carbon-black-cloud/integrations/data-forwarder/quick-setup/#optional-setup-kms-encryption

Additional Information

KMS Bucket Keys are not specifically "required" but are "recommended". The configuration that was approved and added to the developer.carbonblack.com site was tested and validated with Bucket keys enabled.