The following topics are available:

Generating a customer-supplied encryption key

Azure provides several services for storing and managing encryption keys in the cloud. The following table identifies which Azure key management options are supported for Customer-Managed Encryption Keys (CMEK) in iManage Work at cloudimanage.com.

Azure Service

CMEK support in cloudimanage.com

Azure Key Vault (Standard Tier)

Supported

Azure Key Vault (Premium Tier)

Supported

Azure Key Vault Managed HSM

Not supported

Azure Cloud HSM

Not supported

Azure Payment HSM

Not supported

In order to use a customer-managed encryption key to encrypt your data stored in iManage Work, you must first create an encryption key.

You can create an RSA-4096 bit public/private encryption key in your preferred tool, or follow the instructions below to create one with OpenSSL.

CAUTION: After the customer-supplied encryption key is created, immediately escrow the key with a custodian, and share the key with other Azure administrators. This redundancy is crucial, in case the key is lost or accidentally deleted. If the encryption key is lost or destroyed, you'll permanently lose all encrypted data on the iManage Work system.

To create a key pair with OpenSSL:

  1. Download and install an encryption key application, such as OpenSSL, on the client machine.

  2. Create a PEM file with the following command:
    openssl genrsa -aes256 -out private.pem 4096

  3. Enter a secret passphrase for the private key.

  4. Escrow the RSA private key with the escrow custodian.

  5. In addition to the escrowed copy, store a backup of the key and passwords in a separate secure location.

NOTE: Azure no longer supports the backup or restoration of keys to a second vault, and isn't a suitable alternative for key escrow.

  1. Make two copies of the private key and passwords, giving one copy to each of the two key holders.

NOTE: You can't generate a key by using the built-in key generation function in Azure. Azure also provides no means to export the key from its vault.

Azure Information Worksheet

Use this worksheet to record values created during the key vault process. These values will be used later in the key ceremonies within iManage Control Center.

Worksheet: Azure information worksheet

Name

Value

1

Azure key vault DNS name

Example

https://ajubalaw.vault.azure.net/

NOTE: Include a backslash at the end.

Actual

2

The Azure Key Version Key Identifier

Example

https://ajubalaw.vault.azure.net/keys/ajubalaw-1/da93550d9b344d04a212dd06b7e7f4dc

Actual

3

Application ID (also known as client ID)

Example

3fb0c700-536b-4700-9841-61e775400809

Actual

4

Client secret (also known as application password)

Example

xCGRvvvQmKfqwTw[@a@qovRN_Nn72K46

Actual

5

Key Vault Crypto Wrap Unwrap Role

Example

iManage CMEK Wrap-Unwrap Role

Actual

6

Key Vault Crypto Wrap Role

Example

iManage CMEK Wrap-Only Role

Actual

Adding the customer-supplied encryption key to an Azure key vault

Use Microsoft Azure to create the key vaults. Make sure the following notes are incorporated into your steps and the results resemble the examples below.

  1. Create a key vault using the instructions provided in Microsoft Azure help.

    1. Record the Azure key vault DNS name in line 1 of the Azure Information Worksheet.

      For example: https://ajubalaw.vault.azure.net/ 

      NOTE: You must include the final backslash.

    2. Within that key vault, create a key resource. The only required settings are:

      • Include Wrap Key and Unwrap Key.

      • Don't use Set Activation date or Set Expiration date.

    3. Import the customer-supplied encryption key that was created during the Generating a customer-supplied encryption key step.
      This creates a Key Identifier. For example: https://ajubalaw.vault.azure.net/keys/ajubalaw-1/da93550d9b344d04a212dd06b7e7f4dc
      Record the Key Identifier in line 2 of the Azure Information Worksheet.

  2. Register the application.
    For example: 3fb0c700-536b-4700-9841-61e775400809
    Record the Application (client) ID in line 3 of the Azure Information Worksheet.

  3. Create an application secret, also called an application password.

CAUTION: After the client secret is created, immediately record the value and also escrow it with a custodian. You can't retrieve it after you leave that section.

For example: xCGRvvvQmKfqwTw[@a@qovRN_Nn72K46
Record the Client Secret in line 4 of the Azure Information Worksheet. 

CAUTION: When generating the application secret, Azure requires you to specify an expiration date that is two years or less. You MUST ensure you have processes in place to update this secret before its expiry date, or the iManage Cloud will be unable to access the Key Vault, and your content won't be able to be decrypted.

Whenever you have an updated secret, use the instructions in Updating the Azure Key Store client id or secret to also update the secret in iManage Control Center.

  1. Azure Key Vault supports two access-control models: Azure Role-Based Access Control (RBAC) and access policies. Azure RBAC is the default and recommended model. In this step and the next, you’ll create two custom roles for iManage: one for normal key use and one for revoking access.
    Key Vault Crypto Wrap Unwrap role: Grants iManage permission to wrap and unwrap keys for customer-managed key encryption and decryption.
    Key Vault Crypto Wrap role: Grants iManage permission to wrap keys but not unwrap them. Assign this role when you want to revoke access to encrypted data without exposing the key material.

    Perform the following steps to create the Key Vault Crypto Wrap Unwrap role:

    1. Sign in to Microsoft Azure with an administrator account that’s assigned one of the following roles:

      • Owner: Grants full access to manage all resources, including the ability to create custom roles and assign them.

      • User Access Administrator: Lets you manage user access to Azure resources and create custom role definitions.

    2. On the Azure services page, select Subscriptions.

    3. On the Subscriptions page, select the subscription role for which you have the Owner role.

      1. In the dialog that opens, select Access control (IAM).

      2. Select Add > Add custom role.

    4. On the Basics tab in the Create a custom role page:

      1. In the Custom role name field, enter a meaningful name for the role.

      2. In the Description field, optionally enter a meaningful description for the role.

      3. In the Baseline permissions field, select the Start from scratch option.

      4. Select Next.

    5. On the Permissions tab in the Create a custom role page, select Add permissions.

      1. In the Add permissions dialog, search for key vault and then select Microsoft Key Vault.

      2. In the Microsoft.KeyVault permissions dialog, select the Data Actions option.

      3. From the Microsoft.KeyVault/vaults/keys section of the Permission list, select the following permissions:

        • Other: Wrap with Key

        • Other: Unwrap with Key

      4. Select Add.

      5. Select Review + create.

    6. On the Review + create tab in the Create a custom role page, review the role assignments and then select Create.

    7. Record the name of the Key Vault Crypto Wrap Unwrap role on line 5 of the Azure Information Worksheet.

  2. Repeat Step 4 to create the Key Vault Crypto Wrap role.

    1. When adding Microsoft.KeyVault permissions in Step 4.e.iii, only add the Other: Wrap with Key permission to the role.

    2. Record the name of the Key Vault Crypto Wrap role on line 6 of the Azure Information Worksheet.

  3. Apply the Key Vault Crypto Wrap Unwrap role to the app registration. This role grants iManage permission to wrap and unwrap keys for customer-managed key encryption and decryption.

    1. Go back to your newly created Key Vault resource and open its Access control (IAM) tab.

    2. Select Add > Add role assignment.

    3. Search for and select the Key Vault Crypto Wrap Unwrap role, then select Next.

    4. Under Assign access to, select User, group, or service principal.

    5. Select + Select members, search for and choose the name of your registered application, and then select Review + assign.

NOTES:

  • According to the FAQ section, you need to create two Azure Key Vaults. The same custom roles can be applied to both key vaults.

  • To grant iManage the permission to wrap and unwrap keys for customer-managed key encryption and decryption, assign the Key Vault Crypto Wrap Unwrap role to the app registration in Step 6. If you need to revoke access to encrypted data, replace the Key Vault Crypto Wrap Unwrap role with the Key Vault Crypto Wrap role.

  • While Role-Based Access Control (RBAC) is the default and recommended access control model for Azure Key Vault, iManage also supports existing Azure Key Vaults that use the access policy model.

FAQ

Q: How many Azure Key Vaults are required?

A: Two Azure Key Vaults are needed to meet this requirement. Two independent sets of keyholders are required and, as best practice, we recommend no single keyholder has access to both key vaults.

Q: Should we configure two key vaults within the same subscription?

A: We recommend having two independent Azure accounts owned by the firm’s designated keyholders and separately accessible only to these keyholders. For Azure subscription assistance, please reach out to a Microsoft representative.

Q: Can we store more than one key in the same key vault pair?

A: No, the RSA key must be identical between the key vault pair. The iManage CMEK service validates that the RSA keys between the key vault pair are identical.

Q: Can I generate a key using the Azure Key Vault functionality?

A: Generating a key within Azure Key Vault isn't allowed for the following reasons:

  • The key must be identical

  • The key id must not be identical

  • The key holder must be a separate person

A key can't be generated in the Azure Key Vault because the key id can't be modified. Therefore, a key must be created outside of your Azure Key Vault. For instructions on creating a key using an alternate application such as OpenSSL, refer to Generating a customer-supplied encryption key.

Q: How much can we expect to be charged by Azure?

A: The only iManage functions that interact with Azure Key Vault are key wrap and key unwrap. These activities occur about every five minutes, which alone would cost about USD15 per month. Library size, number of users, and amount of activity don't affect the amount of key wrap and key unwrap actions that iManage sends to the Azure Key Vault. For more information on Azure pricing, go to https://azure.microsoft.com/en-us/pricing/details/key-vault/.