Your suggested change has been received. Thank you.

close

Suggest A Change

https://thales.na.market.dpondemand.io/docs/dpod/services/kmo….

back

Google Workspace CSE Resources

Endpoints

search

Please Note:

Endpoints

This section describes how to create, edit, disable/enable, archive, recover, and delete endpoints. Creation of an endpoint requires identity providers. At least one identity provider must be added to an endpoint. Identity providers can be created in advance or when creating the endpoints. This section assumes that you have already created identity providers, as described in Creating Identity Providers.

Creating KACLS Endpoints

To create an endpoint:

  1. Open the Cloud Key Manager Application.

  2. In the left pane, click Services > Google Workspace CSE. The Google Workspace Client Side Encryption page is displayed.

  3. Click Create Endpoint. The Create Endpoint screen is displayed.

  4. Specify a unique Name for the endpoint. This is a mandatory field.

  5. Specify the Authentication Audience. This is a mandatory field.

    Authentication Audience is the ID of the third-party identity provider. For example, for Auth0, it is represented by the Client ID.

  6. Specify the Endpoint URL Hostname. This is a mandatory field. Enter the fully qualified domain name (FQDN) of the CCKM/CipherTrust Manager appliance.

  7. Select an Identity Provider. The options are:

    • All: This is the default option. All the available identity providers will be trusted by the endpoint.

    • Selected: Select this option to select/remove the desired identity providers.

    Optionally, you can add a new identity provider by clicking Create Identity Provider. Refer to Creating Identity Providers for details.

  8. Click Save.

The newly created endpoint appears in the endpoints list, with an Active status. Similarly, add as many endpoints as required.

Every endpoint has an associated endpoint URL. This URL is needed to access the Thales key service. Google Workspace administrators use this URL to configure Google Workspace to communicate with the KACLS.

Viewing Endpoints

The Google Workspace Client Side Encryption page shows the available endpoints. The ENDPOINTS section shows Name, Endpoint URL (or KACLS URL), Status, Key Name, Key ID, and Key Version.

To view details of an endpoint:

  1. Open the Cloud Key Manager Application.

  2. In the left pane, click Services > Google Workspace CSE. The ENDPOINTS section shows the following details:

ColumnDescription
NameName of the endpoint.
Endpoint URL(KACLS URL) URL of the endpoint. This URL is needed to access the Thales key service. Google Workspace administrators use this URL to configure Google Workspace to communicate with the KACLS.
StatusStatus of the endpoint. The status can be:
Active: The endpoint is enabled. An endpoint is active when it is created, and can be disabled, archived, or deleted.
Disabled: The endpoint is disabled and cannot be used for encryption and decryption of data. A disabled endpoint can be enabled, archived, or deleted.
Archived: The endpoint is archived. An archived endpoint can be recovered later, if required.
Key NameName of the linked encryption key.
Key IDID of the linked encryption key. The ID changes on endpoint key rotation.
Key VersionVersion of the encryption key. The key version changes on endpoint key rotation.

To view the perimeters of an endpoint, click the expand icon Expand Icon to the left of the desired endpoint.

Viewing or Editing Endpoints

After an endpoint is created, you can view and modify the linked authentication audience, hostname for the endpoint URL, and identity provider.

To view and edit an endpoint details:

  1. Open the Cloud Key Manager Application.

  2. In the left pane, click Services > Google Workspace CSE.

  3. Under ENDPOINTS, click the overflow icon Overflow Icon corresponding to the endpoint you want to edit.

  4. Click View/Edit. The edit view of the endpoint is shown.

  5. Modify the Authentication Audience, Endpoint URL Hostname, and/or Identity Provider, as appropriate. The name cannot be changed.

  6. Click Save.

The endpoint details are updated.

Rotating Endpoint Keys

Key rotation is process of changing an endpoint's existing key used to encrypt or decrypt the DEK.

To rotate encryption key for an endpoint:

  1. Open the Cloud Key Manager Application.

  2. In the left pane, click Services > Google Workspace CSE.

  3. Under ENDPOINTS, click the overflow icon Overflow Icon corresponding to the desired endpoint.

  4. Click Rotate Keys. A message appears prompting to confirm the action.

  5. Click Rotate Key.

The endpoint key is rotated successfully.

Disabling Endpoints

When an endpoint is not needed for certain period of time, it can be disabled from the CipherTrust Manager.

Before disabling the endpoint, ensure that it is not in use. If an in-use endpoint is disabled, Google Workspace cannot encrypt or decrypt content using the endpoint URL. Also, disabling an endpoint does not delete the associated encryption key.

To disable an endpoint:

  1. Open the Cloud Key Manager Application.

  2. In the left pane, click Services > Google Workspace CSE.

  3. Under ENDPOINTS, click the overflow icon Overflow Icon corresponding to the endpoint you want to disable.

  4. Click Disable.

The endpoint status becomes Disabled.

Enabling Endpoints

When a disabled endpoint is needed again, enable it from the CipherTrust Manager.

To enable an endpoint:

  1. Open the Cloud Key Manager Application.

  2. In the left pane, click Services > Google Workspace CSE.

  3. Under ENDPOINTS, click the overflow icon Overflow Icon corresponding to the endpoint you want to enable.

  4. Click Enable.

The endpoint status becomes Active.

Archiving Endpoints

Whenever needed, you can archive an endpoint from the CipherTrust Manager. An archived endpoint can be recovered later, if needed.

To archive an endpoint:

  1. Open the Cloud Key Manager Application.

  2. In the left pane, click Services > Google Workspace CSE.

  3. Under ENDPOINTS, click the overflow icon Overflow Icon corresponding to the endpoint you want to archive.

  4. Click Archive.

The endpoint status becomes Archived.

Recovering Archived Endpoints

An archived endpoint can be recovered from the CipherTrust Manager. A recovered endpoint can be used again to encrypt and decrypt data.

To recover an archived endpoint:

  1. Open the Cloud Key Manager Application.

  2. In the left pane, click Services > Google Workspace CSE.

  3. Under ENDPOINTS, click the overflow icon Overflow Icon corresponding to the archived endpoint you want to recover.

  4. Click Recover.

The endpoint status becomes Active.

Deleting Endpoints

When an endpoint is no longer needed, delete it from the CipherTrust Manager.

Before deleting the endpoint, ensure that it is not in use. If an in-use endpoint is deleted, Google Workspace cannot encrypt or decrypt content using the endpoint URL. Also, deleting an endpoint does not delete the associated encryption key.

To delete an endpoint:

  1. Open the Cloud Key Manager Application.

  2. In the left pane, click Services > Google Workspace CSE.

  3. Under ENDPOINTS, click the overflow icon Overflow Icon corresponding to the endpoint you want to delete.

  4. Click Delete.

    A warning message appears stating that the endpoint will be deleted permanently. Do you want to delete this endpoint?

  5. Select I wish to delete this endpoint.

  6. Click Delete.

The endpoint is removed from the endpoints list.