Creates a new key-signing key (KSK) associated with a hosted zone
Source:R/route53_operations.R
route53_create_key_signing_key.RdCreates a new key-signing key (KSK) associated with a hosted zone. You can only have two KSKs per hosted zone.
See https://www.paws-r-sdk.com/docs/route53_create_key_signing_key/ for full documentation.
Usage
route53_create_key_signing_key(
CallerReference,
HostedZoneId,
KeyManagementServiceArn,
Name,
Status
)Arguments
- CallerReference
[required] A unique string that identifies the request.
- HostedZoneId
[required] The unique string (ID) used to identify a hosted zone.
- KeyManagementServiceArn
[required] The Amazon resource name (ARN) for a customer managed key in Key Management Service (KMS). The
KeyManagementServiceArnmust be unique for each key-signing key (KSK) in a single hosted zone. To see an example ofKeyManagementServiceArnthat grants the correct permissions for DNSSEC, scroll down to Example.You must configure the customer managed customer managed key as follows:
Status
Enabled
Key spec
ECC_NIST_P256
Key usage
Sign and verify
Key policy
The key policy must give permission for the following actions:
DescribeKey
GetPublicKey
Sign
The key policy must also include the Amazon Route 53 service in the principal for your account. Specify the following:
"Service": "dnssec-route53.amazonaws.com"
For more information about working with a customer managed key in KMS, see Key Management Service concepts.
- Name
[required] A string used to identify a key-signing key (KSK).
Namecan include numbers, letters, and underscores (_).Namemust be unique for each key-signing key in the same hosted zone.- Status
[required] A string specifying the initial status of the key-signing key (KSK). You can set the value to
ACTIVEorINACTIVE.