LogoLogo
SupportDashboard
  • 👋Welcome to FenixPyre
  • Overview
    • 💡What we do
  • FenixPyre for Admins
    • Getting Started
      • Prerequisites Checklist
      • Creating a tenant for your Organization
      • Invite your team members
      • Create your Master Encryption Key
      • Setup SSO and automatic user provisioning
      • Create your first cloud integration
      • Setup User Policies
      • Install FenixPyre Windows Client in a machine
      • Firewall Whitelisting Requirements for FenixPyre Services
    • Admin Dashboard
      • Home
      • User Management
        • Invite your team members
        • Manage Guests
      • Groups Management
      • Installers
        • FenixPyre Windows Client
          • How to download FenixPyre Windows Agent from Installers Page
          • Auto Update and Upgrade Management of FenixPyre Windows Client
      • Reports
      • Integrations
        • SharePoint/OneDrive
          • Overview
          • How to enable FenixPyre integration in SharePoint
          • How to configure SharePoint Integration in Admin Dashboard
          • How to configure Auto Encrypted folders
        • Egnyte
        • Box
          • How to enable FenixPyre integration in Box
          • How to configure Box Integration in the Admin Dashboard
          • How to configure user policy (Protected folder)
      • Sharing Settings
      • Identity & Provisioning
        • Domain Management
          • Primary Domain
          • Guest Domain
        • SAML Single Sign-On (SSO) Setup
          • Set-up SAML SSO with Azure
            • Verify the SAML SSO
            • Sign-in to Admin Dashboard with Azure AD
            • Sign-in to SharePoint integration with Azure AD
          • Set-up SAML SSO with Okta
            • Adding users to Okta Application
            • How to verify SSO sign-in
            • Sign-in to SharePoint integration with Okta
        • Automatic Account Creation
        • SCIM
          • User Management with SCIM(SCIM events)
          • Set-up SCIM for Azure
            • How to provision a user
            • How to de-provision a user?
            • Known limitations
          • Set-up SCIM for OKTA
            • How to provision a user?
            • How to de-provision a user?
            • Known limitations
          • What happens when a user is de-provisioned?
          • Known Limitations
      • Key management
        • Master Encryption Keys
          • Create Master Encryption Key with FenixPyre
          • Setup Bring Your Own Master Encryption Key (BYOMEK) with Azure
            • Configure Azure Key Vault as Bring Your Own Key Provider
            • Create a Master Encryption Key and Store in Azure Key Vault
          • Setup Bring Your Own Master Encryption Key (BYOMEK) with Google HSM
            • Configure Google HSM as Bring Your Own Key Provider
            • Create a Master Encryption Key and Store in Google HSM
            • Import a master encryption key from Google HSM to FenixPyre
      • User Policies
        • Policy Rules Guide
      • User Applications
    • FenixPyre Windows Agent
      • Prerequisites for FenixPyre Windows Client Installation
      • How to download and install windows agent
      • How to install FenixPyre Windows Desktop Client
      • How to install FenixPyre Windows Desktop Client via command line or RMM
      • How to login to FenixPyre Windows Agent
    • Cloud Integrations
      • SharePoint/OneDrive
      • Box
      • On-Prem Secure Sharing Solution
        • Overview
  • FenixPyre For Users
    • SharePoint
      • Install and activate FenixPyre Chrome extension
      • How to encrypt files
      • How to open encrypted files
      • How to share and collaborate with a encrypted file
      • How to share and collaborate with a FenixPyre protected folder
      • How to decrypt files
      • How to view access logs for an encrypted file
      • How to clear browser cache for SharePoint
    • FenixPyre Sharing
      • How to encrypt files
      • How to open encrypted files
        • Supported File types for FenixPyre Sharing Open
      • How to share and collaborate with a encrypted file
      • How to share and collaborate with a FenixPyre protected folder
      • How to view access logs for an encrypted file
      • How to download a file
    • Windows Agent
      • How to login to FenixPyre Windows Agent
      • How to protect/un-protect folders with FenixPyre Windows Agent
      • How to encrypt a file using FenixPyre
      • How to open a file using FenixPyre
      • How to share a file using FenixPyre
      • How to un-install FenixPyre Windows Client
  • FenixPyre for Recipients
    • FenixPyre Sharing Guide
      • How to create new files from a FenixPyre shared link
      • How to request access for a link on FenixPyre
      • How to Create New Folders in a FenixPyre Shared Link
      • How to upload files to a FenixPyre shared link
      • How to download files from a FenixPyre shared link
      • How to co-edit a encrypted file from a FenixPyre shared link
      • How to open a FenixPyre encrypted file shared via SharePoint/OneDrive/Teams
  • FenixPyre Features
    • Offline mode
    • Compliance mode
  • FAQs / Trouble Shooting
    • How to collect FenixPyre agent logs
    • How to reload SharePoint Integration in FenixPyre
    • How to update SharePoint client Certificate
  • Release Notes
    • FenixPyre Windows Client Releases
      • Windows Agent v6.4.0
      • Windows Agent v6.3.0
      • Windows Agent v6.2.0
    • FenixPyre Cloud Releases
      • May 2025
      • March 2025
      • January 2025
  • References
    • Glossary
    • How to Guides
      • How to install WebView2 on your Windows Machine
      • How to enable TLS 1.2 on Windows for Agent Installation?
      • How to install Microsoft Visual C++ Redistributable (x64) 2019 or higher?
      • How to Whitelist FenixPyre's Windows Agent in your Antivirus/EDR/XDR?
      • How to zip and share FenixPyre windows client logs?
  • Group 1
    • Page 1
Powered by GitBook

© 2018-2025 FenixPyre Inc

On this page
  • Setting Up Encryption Key Provider in FenixPyre
  • Video Tutorial

Was this helpful?

  1. FenixPyre for Admins
  2. Admin Dashboard
  3. Key management
  4. Master Encryption Keys
  5. Setup Bring Your Own Master Encryption Key (BYOMEK) with Google HSM

Configure Google HSM as Bring Your Own Key Provider

PreviousSetup Bring Your Own Master Encryption Key (BYOMEK) with Google HSMNextCreate a Master Encryption Key and Store in Google HSM

Last updated 4 months ago

Was this helpful?

Setting Up Encryption Key Provider in FenixPyre

Watch video tutorial


Prerequisites

  • Admin Access in GCP: Ensure you have administrative access to Google Cloud Platform (GCP).

  • Admin Access to FenixPyre Portal: Ensure you have administrative access to the FenixPyre portal to configure the encryption key provider settings.


Setup Process

1. Create or Access a Key Ring

  • Follow to create a key ring or navigate to an existing one.

2. Copy Resource Name

  • Click on the vertical ellipsis (â‹®) next to the key ring and select Copy Resource Name.

3. Update Resource Name in FenixPyre Dashboard

  • Log in to the FenixPyre Dashboard.

  • Navigate to Settings → Security → Key Management → Encryption Key Provider.

  • Paste the resource name into the KeyRing Resource Name field.

  • Add a vault name for identification in the Vault Name text box.

4. Create a Role in GCP Console

  • Navigate back to the GCP console.

  • Go to IAM → Roles.

  • Create a new role with the following permissions:

    • cloudkms.cryptoKeyVersions.create

    • cloudkms.cryptoKeyVersions.get

    • cloudkms.cryptoKeyVersions.useToDecrypt

    • cloudkms.cryptoKeyVersions.useToEncrypt

    • cloudkms.cryptoKeyVersions.useToSign

    • cloudkms.cryptoKeyVersions.useToVerify

    • cloudkms.cryptoKeyVersions.viewPublicKey

    • cloudkms.cryptoKeys.create

    • cloudkms.cryptoKeys.get

    • cloudkms.cryptoKeys.update

    • cloudkms.importJobs.create

    • cloudkms.importJobs.get

    • cloudkms.importJobs.useToImport

    • cloudkms.keyRings.create

    • cloudkms.keyRings.get

    • cloudkms.keyRings.list

    • cloudkms.locations.get

5. Create a Service Account

  • Navigate to the Service Accounts tab.

  • Give your service account a name and click Create and Continue.

  • In the roles field, select the role you just created.

  • Click Done.

  • A new service account will be created.

6. Generate and Download the Encryption Key

  • Select the service account you created in the previous step.

  • Go to the Keys tab and click on Add Key.

  • Choose Create a Key.

  • Select JSON and click Create.

  • A JSON file will be downloaded containing your encryption key.

7. Create Encryption Key Provider in FenixPyre

  • Navigate back to the FenixPyre Dashboard.

  • Use the downloaded JSON file to create your own encryption key provider with GCP in FenixPyre by following the on-screen instructions for uploading or configuring the key.


Video Tutorial

Follow to create a new role.

Google's documentation
Google’s documentation
here