> ## Documentation Index
> Fetch the complete documentation index at: https://docs-staging-update-anonymous-sessons-ea.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

> Activez et configurez les Customer Managed Keys (BYOK) pour votre tenant Auth0 à l’aide du Auth0 Dashboard.

# Configurer les Customer Managed Keys avec le Dashboard

Auth0 protège les secrets et les données de votre tenant à l’aide d’une Auth0 Environment Root Key, au sommet de la hiérarchie de clés du chiffrement par enveloppe. L’Auth0 Environment Root Key et la Customer Provided Root Key sont stockées dans le module matériel de sécurité (HSM) du fournisseur de services infonuagiques Auth0 correspondant, AWS ou Azure.

<h2 id="bring-your-own-key">
  Bring Your Own Key
</h2>

Avec Bring Your Own Key, les utilisateurs ayant le [Key Management Editor role](/docs/fr-ca/get-started/manage-dashboard-access/add-dashboard-users) peuvent utiliser le <Tooltip tip="Auth0 Dashboard : principal produit d’Auth0 pour configurer vos services." cta="Voir le glossaire" href="/docs/fr-ca/glossary?term=Auth0+Dashboard">Auth0 Dashboard</Tooltip> pour remplacer l’Auth0 Environment Root Key par défaut par leur propre Customer Provided Root Key.

Les clients peuvent téléverser de façon sécuritaire leur propre Root Key, qui contient leur propre matériel cryptographique, afin de :

* Répondre à des exigences personnalisées de génération et de provenance de clé pour l’Environment Root Key.
* Répondre à des exigences précises d’installation ou de durée de vie de clé pour l’Environment Root Key.

<Warning>
  En important votre propre Customer Provided Root Key avec Bring Your Own Key, vous retirez implicitement à Auth0 la gestion du cycle de vie de la Customer Provided Root Key, sauf en ce qui concerne sa suppression.
</Warning>

Pour commencer, accédez à Dashboard > Settings > Encryption Keys

<Frame>
  <img src="https://mintcdn.com/docs-staging-update-anonymous-sessons-ea/KUZyZ8QYVXJvgdUz/docs/images/cdy7uua7fh8z/1qmfCSl7cOugrHIAdxSyAt/6c7d7185920e61809d9423c8e3d4c4f2/Encryption_Keys_-_EN.png?fit=max&auto=format&n=KUZyZ8QYVXJvgdUz&q=85&s=b690e28d7198558565860fcd44d92c2f" alt="Dashboard > Settings > Clés de chiffrement" data-og-width="1162" width="1162" data-og-height="577" height="577" data-path="docs/images/cdy7uua7fh8z/1qmfCSl7cOugrHIAdxSyAt/6c7d7185920e61809d9423c8e3d4c4f2/Encryption_Keys_-_EN.png" data-optimize="true" data-opv="3" srcset="https://mintcdn.com/docs-staging-update-anonymous-sessons-ea/KUZyZ8QYVXJvgdUz/docs/images/cdy7uua7fh8z/1qmfCSl7cOugrHIAdxSyAt/6c7d7185920e61809d9423c8e3d4c4f2/Encryption_Keys_-_EN.png?w=280&fit=max&auto=format&n=KUZyZ8QYVXJvgdUz&q=85&s=27bb6e0849b17ad18fb1a97bc39201dd 280w, https://mintcdn.com/docs-staging-update-anonymous-sessons-ea/KUZyZ8QYVXJvgdUz/docs/images/cdy7uua7fh8z/1qmfCSl7cOugrHIAdxSyAt/6c7d7185920e61809d9423c8e3d4c4f2/Encryption_Keys_-_EN.png?w=560&fit=max&auto=format&n=KUZyZ8QYVXJvgdUz&q=85&s=4d898f81a0913e2f05cc6a58a957b1b1 560w, https://mintcdn.com/docs-staging-update-anonymous-sessons-ea/KUZyZ8QYVXJvgdUz/docs/images/cdy7uua7fh8z/1qmfCSl7cOugrHIAdxSyAt/6c7d7185920e61809d9423c8e3d4c4f2/Encryption_Keys_-_EN.png?w=840&fit=max&auto=format&n=KUZyZ8QYVXJvgdUz&q=85&s=4ea365aad53880a75be5faaab65df415 840w, https://mintcdn.com/docs-staging-update-anonymous-sessons-ea/KUZyZ8QYVXJvgdUz/docs/images/cdy7uua7fh8z/1qmfCSl7cOugrHIAdxSyAt/6c7d7185920e61809d9423c8e3d4c4f2/Encryption_Keys_-_EN.png?w=1100&fit=max&auto=format&n=KUZyZ8QYVXJvgdUz&q=85&s=87be2f4b96eacfdfcbeb9ce4259ae162 1100w, https://mintcdn.com/docs-staging-update-anonymous-sessons-ea/KUZyZ8QYVXJvgdUz/docs/images/cdy7uua7fh8z/1qmfCSl7cOugrHIAdxSyAt/6c7d7185920e61809d9423c8e3d4c4f2/Encryption_Keys_-_EN.png?w=1650&fit=max&auto=format&n=KUZyZ8QYVXJvgdUz&q=85&s=72ef4deb178d8d06304a324d489c8263 1650w, https://mintcdn.com/docs-staging-update-anonymous-sessons-ea/KUZyZ8QYVXJvgdUz/docs/images/cdy7uua7fh8z/1qmfCSl7cOugrHIAdxSyAt/6c7d7185920e61809d9423c8e3d4c4f2/Encryption_Keys_-_EN.png?w=2500&fit=max&auto=format&n=KUZyZ8QYVXJvgdUz&q=85&s=e4f0a93f49f11d9d73c8cc2f287ca7e7 2500w" />
</Frame>

Sélectionnez **Upload Key** pour lancer le processus d’importation de votre Customer Provided Root Key. Cela ouvrira la boîte de dialogue d’importation :

<Frame>
  <img src="https://mintcdn.com/docs-staging-update-anonymous-sessons-ea/KUZyZ8QYVXJvgdUz/docs/images/cdy7uua7fh8z/1GJPgT1Be7Wm6G6ldCVW4q/96e5a326aa643f29bb50aea76fce27aa/image__2_.png?fit=max&auto=format&n=KUZyZ8QYVXJvgdUz&q=85&s=ce635d40bb5969a5cf8730ed1a4687f1" alt="Dashboard > Settings > Clés de chiffrement > Téléverser" data-og-width="629" width="629" data-og-height="462" height="462" data-path="docs/images/cdy7uua7fh8z/1GJPgT1Be7Wm6G6ldCVW4q/96e5a326aa643f29bb50aea76fce27aa/image__2_.png" data-optimize="true" data-opv="3" srcset="https://mintcdn.com/docs-staging-update-anonymous-sessons-ea/KUZyZ8QYVXJvgdUz/docs/images/cdy7uua7fh8z/1GJPgT1Be7Wm6G6ldCVW4q/96e5a326aa643f29bb50aea76fce27aa/image__2_.png?w=280&fit=max&auto=format&n=KUZyZ8QYVXJvgdUz&q=85&s=9c5ff4b55c30dde53a8f2c8d62034b84 280w, https://mintcdn.com/docs-staging-update-anonymous-sessons-ea/KUZyZ8QYVXJvgdUz/docs/images/cdy7uua7fh8z/1GJPgT1Be7Wm6G6ldCVW4q/96e5a326aa643f29bb50aea76fce27aa/image__2_.png?w=560&fit=max&auto=format&n=KUZyZ8QYVXJvgdUz&q=85&s=573981110ad0484022fb68dac0f6849c 560w, https://mintcdn.com/docs-staging-update-anonymous-sessons-ea/KUZyZ8QYVXJvgdUz/docs/images/cdy7uua7fh8z/1GJPgT1Be7Wm6G6ldCVW4q/96e5a326aa643f29bb50aea76fce27aa/image__2_.png?w=840&fit=max&auto=format&n=KUZyZ8QYVXJvgdUz&q=85&s=5a22ea883f567ef0f3da6f80931a2f96 840w, https://mintcdn.com/docs-staging-update-anonymous-sessons-ea/KUZyZ8QYVXJvgdUz/docs/images/cdy7uua7fh8z/1GJPgT1Be7Wm6G6ldCVW4q/96e5a326aa643f29bb50aea76fce27aa/image__2_.png?w=1100&fit=max&auto=format&n=KUZyZ8QYVXJvgdUz&q=85&s=2e417768f368159cc67339dfa4701953 1100w, https://mintcdn.com/docs-staging-update-anonymous-sessons-ea/KUZyZ8QYVXJvgdUz/docs/images/cdy7uua7fh8z/1GJPgT1Be7Wm6G6ldCVW4q/96e5a326aa643f29bb50aea76fce27aa/image__2_.png?w=1650&fit=max&auto=format&n=KUZyZ8QYVXJvgdUz&q=85&s=13c15d5f57849d4b0591b9ab63985f9d 1650w, https://mintcdn.com/docs-staging-update-anonymous-sessons-ea/KUZyZ8QYVXJvgdUz/docs/images/cdy7uua7fh8z/1GJPgT1Be7Wm6G6ldCVW4q/96e5a326aa643f29bb50aea76fce27aa/image__2_.png?w=2500&fit=max&auto=format&n=KUZyZ8QYVXJvgdUz&q=85&s=5635229f5a4c148a6a857a711911f60e 2500w" />
</Frame>

Lorsque vous sélectionnez **Upload Key**, puis **Download**, le processus Bring Your Own Key est lancé :

1. Une clé d’enveloppement publique est créée et téléchargée sur votre système.
2. Prenez la clé d’enveloppement publique et utilisez-la pour envelopper votre propre matériel cryptographique à l’aide de votre propre système de gestion des clés afin de créer une clé de chiffrement enveloppée (la Customer Provided Root Key).
3. Téléversez votre clé de chiffrement enveloppée et sélectionnez **Save**.

<Callout icon="file-lines" color="#0EA5E9" iconType="regular">
  Une fois téléversée, la clé de chiffrement enveloppée remplace l’Auth0 Environment Root Key dans le module matériel de sécurité (AWS ou Azure) en tant que Customer Provided Root Key.
</Callout>

<h2 id="cryptographic-material-requirements">
  Exigences relatives au matériel cryptographique
</h2>

Utilisez votre système de gestion de clés pour envelopper votre propre matériel cryptographique à l’aide de la clé d’enveloppement publique et créer la clé de chiffrement enveloppée. Utilisez les paramètres suivants pour l’algorithme [CKM\_RSA\_AES\_KEY\_WRAP](https://docs.oasis-open.org/pkcs11/pkcs11-curr/v2.40/cos01/pkcs11-curr-v2.40-cos01.html#_Toc408226894), selon votre fournisseur de services infonuagiques Auth0 (AWS ou Azure) :

<h3 id="auth0-on-aws-cloud">
  Auth0 on AWS cloud
</h3>

* Longueur de la clé d’enveloppement publique : 3072 bits
* Algorithme : CKG\_MGF1\_SHA256
* Longueur de la clé AES temporaire pour CKM\_AES\_KEY\_WRAP\_PAD : 256 bits
* Type de la clé racine fournie par le client : clé symétrique AES de 256 bits

<h3 id="auth0-on-azure-cloud">
  Auth0 on Azure
</h3>

* Longueur de la clé d’enveloppement publique : 2048 bits
* Algorithme : CKG\_MGF1\_SHA-1
* Longueur de la clé AES temporaire pour CKM\_AES\_KEY\_WRAP\_PAD : 256 bits
* Type de Customer Provided Root Key : clé privée RSA de 2048 bits
* Encodage de la clé privée : PKCS #8 - ASN.1 DER
