<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Configuring AWS KMS policy for tenant encryption in Management &amp; Governance</title>
    <link>https://community.qlik.com/t5/Management-Governance/Configuring-AWS-KMS-policy-for-tenant-encryption/m-p/2492147#M29137</link>
    <description>&lt;P&gt;Hello, I am attempting to implement tenant encryption for Qlik Cloud using a key from AWS KMS. I am quite new to this, so I have tried to carefully follow the &lt;A href="https://help.qlik.com/en-US/cloud-services/Subsystems/Hub/Content/Sense_Hub/Admin/mc-configure-tenant-encryption.htm" target="_blank" rel="noopener"&gt;instructions detailed here&lt;/A&gt;. However, when I attempt to create the key provider within QMC, I receive the following error:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Error code: The policy of the provided key does not allow to know key type is Single region or Multi region&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Has anyone experienced this and/or can guide me to a solution? Thanks in advance for any suggestions.&lt;/P&gt;</description>
    <pubDate>Wed, 29 Jan 2025 16:21:29 GMT</pubDate>
    <dc:creator>ArrogantAardvark</dc:creator>
    <dc:date>2025-01-29T16:21:29Z</dc:date>
    <item>
      <title>Configuring AWS KMS policy for tenant encryption</title>
      <link>https://community.qlik.com/t5/Management-Governance/Configuring-AWS-KMS-policy-for-tenant-encryption/m-p/2492147#M29137</link>
      <description>&lt;P&gt;Hello, I am attempting to implement tenant encryption for Qlik Cloud using a key from AWS KMS. I am quite new to this, so I have tried to carefully follow the &lt;A href="https://help.qlik.com/en-US/cloud-services/Subsystems/Hub/Content/Sense_Hub/Admin/mc-configure-tenant-encryption.htm" target="_blank" rel="noopener"&gt;instructions detailed here&lt;/A&gt;. However, when I attempt to create the key provider within QMC, I receive the following error:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Error code: The policy of the provided key does not allow to know key type is Single region or Multi region&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Has anyone experienced this and/or can guide me to a solution? Thanks in advance for any suggestions.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2025 16:21:29 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Configuring-AWS-KMS-policy-for-tenant-encryption/m-p/2492147#M29137</guid>
      <dc:creator>ArrogantAardvark</dc:creator>
      <dc:date>2025-01-29T16:21:29Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring AWS KMS policy for tenant encryption</title>
      <link>https://community.qlik.com/t5/Management-Governance/Configuring-AWS-KMS-policy-for-tenant-encryption/m-p/2492450#M29138</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This may help you:&amp;nbsp;&lt;A href="https://community.qlik.com/t5/Official-Support-Articles/QCDI-Configuring-AWS-KMS-fails-with-The-policy-of-the-provided/ta-p/2469639" target="_blank"&gt;QCDI: Configuring AWS KMS fails with The policy of... - Qlik Community - 2469639&lt;/A&gt;&lt;BR /&gt;Then I think you need to check if you're using a multiple region KMS Key based on your Qlik tenant region and its backup&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Best&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2024 08:18:33 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Configuring-AWS-KMS-policy-for-tenant-encryption/m-p/2492450#M29138</guid>
      <dc:creator>mpc</dc:creator>
      <dc:date>2024-11-13T08:18:33Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring AWS KMS policy for tenant encryption</title>
      <link>https://community.qlik.com/t5/Management-Governance/Configuring-AWS-KMS-policy-for-tenant-encryption/m-p/2492557#M29139</link>
      <description>&lt;P&gt;Thanks for the reply--the resource you pointed to helped get me on the right track. Ultimately, the problem was that my policy was misconfigured. With the multi-region key, the &lt;A href="https://docs.aws.amazon.com/kms/latest/APIReference/API_DescribeKey.html" target="_self"&gt;DescribeKey KMS action&lt;/A&gt; is required. My policy was set up for a single region even though the key was created as multi-region. I appreciate the help!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2024 14:56:45 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Configuring-AWS-KMS-policy-for-tenant-encryption/m-p/2492557#M29139</guid>
      <dc:creator>ArrogantAardvark</dc:creator>
      <dc:date>2024-11-13T14:56:45Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring AWS KMS policy for tenant encryption</title>
      <link>https://community.qlik.com/t5/Management-Governance/Configuring-AWS-KMS-policy-for-tenant-encryption/m-p/2492564#M29140</link>
      <description>&lt;P&gt;Wlcm and thanks for your return ! It will help others for sure !&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2024 15:27:21 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Management-Governance/Configuring-AWS-KMS-policy-for-tenant-encryption/m-p/2492564#M29140</guid>
      <dc:creator>mpc</dc:creator>
      <dc:date>2024-11-13T15:27:21Z</dc:date>
    </item>
  </channel>
</rss>

