| Configuring for Object Storage and HDFS / Configuring the Transfer Server for AWS S3 Private Cloud | |
AWS Key Management Service (KMS) is an Amazon web service that uses customer master keys to encrypt objects in AWS S3 cloud storage. You can configure S3 server-side encryption with KMS system-wide or on a user-by-user basis.
Prerequisites:
To enable system-wide S3 server-side encryption with KMS, configure the s3.properties file on the server.
To enable S3 server-side encryption with KMS for specific users, append ?server-side-encryption=AWS_KMS to the S3 docroot of the transfer users. You can do this in IBM Aspera Console or using the asconfigurator tool. The examples below use asconfigurator.