Google Cloud Integration Guide V1.2

Total Page:16

File Type:pdf, Size:1020Kb

Google Cloud Integration Guide V1.2 KEYNEXUS Google Cloud Integration Guide v1.2 07/2018 Introduction KeyNexus Copyright Notice Copyright 2018 KeyNexus. All rights reserved. Information in this document is subject to change without notice. The software described in this document is furnished under a license agreement or nondisclosure agreement. No part of this publication may be reproduced, stored in a retrieval system, or transmitted in any form or any means electronic or mechanical, including photocopying and recording for any purpose other than the purchaser's personal use without written permission. Page 2 of 44 KeyNexus KeyNexus Introduction Table of Contents Introduction ................................................................................................................................ 5 Prerequisites .............................................................................................................................. 6 Google Cloud SDK ....................................................................................................................39 KeyNexus Patches .............................................................................................................41 Google Storage Utililty ..............................................................................................................41 Deploying KeyNexus on Google Cloud ...................................................................................... 6 Create a new Google Cloud Platform project .......................................................................... 6 Create a new Google Cloud Platform bucket .......................................................................... 7 Upload the KeyNexus image file to the Google Storage bucket .............................................. 8 Create an Image from the Google Cloud Platform .................................................................. 8 Create an Instance from Google Cloud Platform .................................................................... 9 KeyNexus Configuration ...........................................................................................................10 KeyNexus Setup ....................................................................................................................10 Cluster Nodes ....................................................................................................................12 Configuring KeyNexus ...........................................................................................................15 Groups ..................................................................................................................................16 Add a group .......................................................................................................................17 Delete a group ...................................................................................................................17 View Users in a Group .......................................................................................................18 Search for a Group ............................................................................................................18 Keys ......................................................................................................................................18 Add a new key ...................................................................................................................19 Import Custom Keys ..........................................................................................................22 Key Details .........................................................................................................................24 Key Rotation ......................................................................................................................25 Add Batch Keys through the API ........................................................................................31 Users .....................................................................................................................................34 Create a New User ............................................................................................................34 Authentication Certificate ...................................................................................................36 Delete a User .....................................................................................................................38 KeyNexus page 3 of 44 Introduction KeyNexus Encrypting and Decrypting objects on Google Cloud Platform ...............................................39 Google Cloud Disk Encryption and Decryption ...................................................................42 Encrypting and decrypting objects .....................................................................................42 Page 4 of 44 KeyNexus KeyNexus Introduction Introduction Google Cloud Platform is a cloud storage platform for storing and retrieving data. It provides a simple programming interface which enables developers to take advantage of Google's own systems to perform data operations in a secure and cost-effective manner. Google Cloud Platform stores objects that are organized into basic storage containers called buckets. All requests are authorized using an access control list (ACL) associated with each bucket and object, or with gsutil, a Python application that allows access to Google Storage through the command line. Google Cloud Platform provides a range of programming languages to choose from when creating applications. These languages are supported by client libraries that allow applications to communicate with Google Cloud Storage. The libraries take care of the HTTP protocol details when using the Google Cloud Storage APIs. This guide provides the instructions for the following tasks: • Installing the Google Cloud SDK • Creating a bucket, uploading the KeyNexus VMDK file, and starting an instance on Google Cloud Platform. • Installing and configuring the KeyNexus patches. • Instructions for creating KeyNexus groups, users and keys in the KeyNexus portal. • Instructions for the scripts used to encrypt and decrypt objects stored on the Google Cloud Platform. Important: This document provides the instructions required to create a bucket, upload the KeyNexus tar.gz file and set up an KeyNexus instance on Google Cloud Platform. This does not mean, however, that KeyNexus must be running on Google Cloud Platform in order to operate as a Key Management System for your files. One of the most powerful features of KeyNexus is its ability to operate independently of any cloud platform. This document was created using KeyNexus Web Portal version 1.10. Using a version of this product other than the one used in this guide may require a different workflow from the one provided here in order to achieve a successful result. The complete set of Google Cloud Platform documentation can be found at https://cloud.google.com/docs/. KeyNexus page 5 of 44 Prerequisites KeyNexus Prerequisites Before proceeding with the configuration and deployment tasks, make sure the following tasks have been performed: • Download and Install the Google Cloud SDK • Download the KeyNexus gcloud integration package. It includes this document, patch files and sample JSON files. Talk to your KeyNexus Representative for access to these files. • Download the keynexus.tar.gz file. Talk to your KeyNexus Representative for access to this file. Deploying KeyNexus on Google Cloud This section provides instructions for the initial activation of Google Cloud Platform, creating a new project, creating a new bucket and uploading the KeyNexus file to that bucket. Once the file is successfully uploaded, it can be used to create an image. Note: These instructions are restricted to the steps necessary to set up an instance of the KeyNexus Web Portal. For complete instructions relating to Google Cloud platform, refer to the https://cloud.google.com/docs/. Create a new Google Cloud Platform project If you already have a project created in Google Cloud Platform, continue on to Create a new Google Cloud Platform bucket. 1. Open Google Cloud Platform Console. 2. Click the Select a project dropdown on the Google Cloud Platform header. This opens the Select dialog. Page 6 of 44 KeyNexus KeyNexus Deploying KeyNexus on Google Cloud 3. Click New Project. The New Project page appears. 4. Enter the project name, organization and select a location using the Browse button and selecting a folder from the list. 5. Click Create. Create a new Google Cloud Platform bucket Once the project is created, you can create a new bucket. A bucket in Cloud Storage is the container for all data stored in the Cloud Storage project. If you already have a bucket created, continue on to Upload the KeyNexus image file to the Google Storage bucket. 1. Click the Navigation Menu button to bring up the Products and Services menu. Select Storage > Browser from the menu. This brings you to the Browser page. 2. Click Create Bucket. The Create a Bucket dialog appears. 1. Enter a name for the bucket. This name has to be unique from any other bucket on Google Cloud storage. 2. Select a storage class for the bucket from one of the Storage Class options. 3. Select a location from the Location dropdown. 4. Click Show advanced settings. Click Specify labels and Add label to provide additional values to assist in organizing your buckets. (Optional) KeyNexus page 7 of 44 Deploying
Recommended publications
  • Google Cloud Issue Summary Multiple Products - 2020-08-19 All Dates/Times Relative to US/Pacific
    Google Cloud Issue Summary Multiple Products - 2020-08-19 All dates/times relative to US/Pacific Starting on August 19, 2020, from 20:55 to 03:30, multiple G Suite and Google Cloud Platform products experienced errors, unavailability, and delivery delays. Most of these issues involved creating, uploading, copying, or delivering content. The total incident duration was 6 hours and 35 minutes, though the impact period differed between products, and impact was mitigated earlier for most users and services. We understand that this issue has impacted our valued customers and users, and we apologize to those who were affected. DETAILED DESCRIPTION OF IMPACT Starting on August 19, 2020, from 20:55 to 03:30, Google Cloud services exhibited the following issues: ● Gmail: The Gmail service was unavailable for some users, and email delivery was delayed. About ​ 0.73% of Gmail users (both consumer and G Suite) active within the preceding seven days experienced 3 or more availability errors during the outage period. G Suite customers accounted for 27% of affected Gmail users. Additionally, some users experienced errors when adding attachments to messages. Impact on Gmail was mitigated by 03:30, and all messages delayed by this incident have been delivered. ● Drive: Some Google Drive users experienced errors and elevated latency. Approximately 1.5% of Drive ​ users (both consumer and G Suite) active within the preceding 24 hours experienced 3 or more errors during the outage period. ● Docs and Editors: Some Google Docs users experienced issues with image creation actions (for ​ example, uploading an image, copying a document with an image, or using a template with images).
    [Show full text]
  • System and Organization Controls (SOC) 3 Report Over the Google Cloud Platform System Relevant to Security, Availability, and Confidentiality
    System and Organization Controls (SOC) 3 Report over the Google Cloud Platform System Relevant to Security, Availability, and Confidentiality For the Period 1 May 2020 to 30 April 2021 Google LLC 1600 Amphitheatre Parkway Mountain View, CA, 94043 650 253-0000 main Google.com Management’s Report of Its Assertions on the Effectiveness of Its Controls Over the Google Cloud Platform System Based on the Trust Services Criteria for Security, Availability, and Confidentiality We, as management of Google LLC ("Google" or "the Company") are responsible for: • Identifying the Google Cloud Platform System (System) and describing the boundaries of the System, which are presented in Attachment A • Identifying our service commitments and system requirements • Identifying the risks that would threaten the achievement of its service commitments and system requirements that are the objectives of our System, which are presented in Attachment B • Identifying, designing, implementing, operating, and monitoring effective controls over the Google Cloud Platform System (System) to mitigate risks that threaten the achievement of the service commitments and system requirements • Selecting the trust services categories that are the basis of our assertion We assert that the controls over the System were effective throughout the period 1 May 2020 to 30 April 2021, to provide reasonable assurance that the service commitments and system requirements were achieved based on the criteria relevant to security, availability, and confidentiality set forth in the AICPA’s
    [Show full text]
  • Google Managed Ssl Certificate Pricing
    Google Managed Ssl Certificate Pricing Mucous Montague never carcases so radiantly or te-heeing any news southward. Alary Philip transhipping patrilineally while Fletcher always cobwebbed his wreckfish seres bifariously, he enswathes so baggily. Quent attitudinised his truce threw connubial, but tachistoscopic Clarence never wived so reversedly. Why they originated from google managed ssl certificate is Try 90-day Trial SSL Certificate before having real capital to test cert's functionality. ZeroSSL Free SSL Certificates and SSL Tools. A user is far behind likely to buy would you school your affect is secure. You require purchase that single site certificate a multiple-domains certificate SAN Looking for. GlobalSign's Managed PKI platform significantly lowers the sale Cost of Ownership for SSL by reducing the man hours needed to manage certificates and. If you must verify that a nice to edit an ai format is most disliked by the site that point to procure, for cost of managed ssl policies do not working. July 201 Google Chrome made it official If their site doesn't have a security certificate. Best Websites to Buy SSL Certificates 7year & up. Step 1 Purchase your SSL certificate from a reputable vendor into your. Data is slightly different prices are authenticated as a different scenarios where i have verified that does, thank you have been confirmed. But when using its pricing should be misleading because i set. Introducing managed SSL for Google App Engine googblogs. Installing an SSL certificate on Google App Engine Hosting. Low pricing a private global network improved performance and features. Analytics tech notes Adobe Analytics for Google Analytics users.
    [Show full text]
  • Cloudpools and Google Cloud Architectural Overview, Considerations, and Best Practices
    Technical White Paper Dell EMC PowerScale: CloudPools and Google Cloud Architectural overview, considerations, and best practices Abstract This white paper provides an overview of Dell EMC™ PowerScale™ CloudPools software in OneFS™ 9.1.0.0. It describes its policy-based capabilities that can reduce storage costs and optimize storage by automatically moving infrequently accessed data to Google Cloud. April 2021 H17993.3 Revisions Revisions Date Description October 2019 Initial release June 2020 Updated best practices October 2020 Updated CloudPools operations April 2021 Updated best practices Acknowledgments Author: Jason He ([email protected]) Dell EMC and the authors of this document welcome your feedback on this white paper. This document may contain certain words that are not consistent with Dell's current language guidelines. Dell plans to update the document over subsequent future releases to revise these words accordingly. This document may contain language from third party content that is not under Dell's control and is not consistent with Dell's current guidelines for Dell's own content. When such third party content is updated by the relevant third parties, this document will be revised accordingly. The information in this publication is provided “as is.” Dell Inc. makes no representations or warranties of any kind with respect to the information in this publication, and specifically disclaims implied warranties of merchantability or fitness for a particular purpose. Use, copying, and distribution of any software described in this publication requires an applicable software license. Copyright © 2019 Dell Inc. or its subsidiaries. All Rights Reserved. Dell, EMC, Dell EMC and other trademarks are trademarks of Dell Inc.
    [Show full text]
  • Google Cloud / Google Maps API Custom Software Solutions for Geospatial Information Needs
    Google Cloud / Google Maps API Custom Software Solutions for Geospatial Information Needs Sanborn is a Service Partner within the Google Cloud Platform Partner Program. Google Cloud Platform is a set of modular cloud-based services that allow you to create anything from simple websites to complex applications. We have a team of Google Qualified Cloud Platform developers fully certified in five disciplines critical for building effective client solutions. Sanborn can provide Google Cloud services and solutions to help clients build and run geospatial applications to store / access data from the same infrastructure that allows Google to return billions of search results in milliseconds. Building business solutions on Google’s cloud platform allows Sanborn to eliminate concerns about future scalability and lack of infrastructure. As a Google Cloud Platform Channel Partner, Sanborn helps clients design, develop and manage new cloud-based solutions. Customers benefit by engaging with Sanborn as a result of our investment in developing the skills needed to build these powerful new solutions on top of Google’s Cloud Platform. Sanborn Google Certified Developers Can Build Client Google Cloud Platform Products Solutions Leveraging: Enable Sanborn Customers to Implement: Google Cloud Storage Google Big Query Google App Engine Google Compute Engine Cloud Storage Solutions: such as high-end backup Google Cloud SQL and recovery, using Google Cloud Storage with Service Level Agreements that include guaranteed monthly uptime that’s greater than 99%. Sanborn Google Cloud Services Include: Cloud App Solutions: such as web-based analysis, Application Services Platform as a service assessment, and visualization apps and websites, using Google App Engine and Google Cloud SQL.
    [Show full text]
  • Economic and Social Impacts of Google Cloud September 2018 Economic and Social Impacts of Google Cloud |
    Economic and social impacts of Google Cloud September 2018 Economic and social impacts of Google Cloud | Contents Executive Summary 03 Introduction 10 Productivity impacts 15 Social and other impacts 29 Barriers to Cloud adoption and use 38 Policy actions to support Cloud adoption 42 Appendix 1. Country Sections 48 Appendix 2. Methodology 105 This final report (the “Final Report”) has been prepared by Deloitte Financial Advisory, S.L.U. (“Deloitte”) for Google in accordance with the contract with them dated 23rd February 2018 (“the Contract”) and on the basis of the scope and limitations set out below. The Final Report has been prepared solely for the purposes of assessment of the economic and social impacts of Google Cloud as set out in the Contract. It should not be used for any other purposes or in any other context, and Deloitte accepts no responsibility for its use in either regard. The Final Report is provided exclusively for Google’s use under the terms of the Contract. No party other than Google is entitled to rely on the Final Report for any purpose whatsoever and Deloitte accepts no responsibility or liability or duty of care to any party other than Google in respect of the Final Report and any of its contents. As set out in the Contract, the scope of our work has been limited by the time, information and explanations made available to us. The information contained in the Final Report has been obtained from Google and third party sources that are clearly referenced in the appropriate sections of the Final Report.
    [Show full text]
  • Frequently Asked Questions for Google Bigquery Connector
    Frequently Asked Questions for Google BigQuery Connector © Copyright Informatica LLC 2017, 2021. Informatica, the Informatica logo, and Informatica Cloud are trademarks or registered trademarks of Informatica LLC in the United States and many jurisdictions throughout the world. A current list of Informatica trademarks is available on the web at https:// www.informatica.com/trademarks.html. Abstract This article describes frequently asked questions about using Google BigQuery Connector to read data from and write data to Google BigQuery. Supported Versions • Cloud Data Integration Table of Contents General Questions............................................................ 2 Performance Tuning Questions................................................... 5 General Questions What is Google Cloud Platform? Google Cloud Platform is a set of public cloud computing services offered by Google. It provides a range of hosted services for compute, storage, and application development that run on Google hardware. Google Cloud Platform services can be accessed by software developers, cloud administrators, and other enterprise IT professionals over the public internet or through a dedicated network connection. Google Cloud Platform provides Google BigQuery to perform data analytics on large datasets. How can I access Google Cloud Platform? You must create a Google service account to access Google Cloud Platform. To create a Google service account, click the following URL: https://cloud.google.com/ What are the permissions required for the Google service
    [Show full text]
  • Google Cloud Security Whitepapers
    1 Google Cloud Security Whitepapers March 2018 Google Cloud Encryption at Rest in Encryption in Transit in Application Layer Infrastructure Security Google Cloud Google Cloud Transport Security Design Overview in Google Cloud 2 Table of Contents Google Cloud Infrastructure Security Design Overview . 3 Encryption at Rest in Google Cloud . 23 Encryption in Transit in Google Cloud . 43 Application Layer Transport Security in Google Cloud . 75 3 A technical whitepaper from Google Cloud 4 Table of Contents Introduction . 7 Secure Low Level Infrastructure . 8 Security of Physical Premises Hardware Design and Provenance Secure Boot Stack and Machine Identity Secure Service Deployment . 9 Service Identity, Integrity, and Isolation Inter-Service Access Management Encryption of Inter-Service Communication Access Management of End User Data Secure Data Storage . 14 Encryption at Rest Deletion of Data Secure Internet Communication . 15 Google Front End Service Denial of Service (DoS) Protection User Authentication Operational Security . 17 Safe Software Development Keeping Employee Devices and Credentials Safe Reducing Insider Risk Intrusion Detection 5 Securing the Google Cloud Platform (GCP) . .. 19 Conclusion . 21 Additional Reading . 22 The content contained herein is correct as of January 2017, and represents the status quo as of the time it was written. Google’s security policies and systems may change going forward, as we continually improve protection for our customers. 6 CIO-level summary • Google has a global scale technical infrastructure designed to provide security through the entire information processing lifecycle at Google. This infrastructure provides secure deployment of services, secure storage of data with end user privacy safeguards, secure communications between services, secure and private communication with customers over the internet, and safe operation by administrators.
    [Show full text]
  • HYCU for Google Cloud Compatibility Matrix
    COMPATIBILITY MATRIX HYCU Data Protection as a Service for Google Cloud Service update date: September 2021 Document release date: September 2021 COMPATIBILITY MATRIX Legal notices Copyright notice © 2021 HYCU. All rights reserved. This document contains proprietary information, which is protected by copyright. No part of this document may be photocopied, reproduced, distributed, transmitted, stored in a retrieval system, modified or translated to another language in any form by any means, without the prior written consent of HYCU. Trademarks HYCU logos, names, trademarks and/or service marks and combinations thereof are the property of HYCU or its affiliates. Other product names are the property of their respective trademark or service mark holders and are hereby acknowledged. GCP™, GKE™, Google Chrome™, Google Cloud™, Google Cloud Platform™, Google Cloud Storage™, and Google Compute Engine™ are trademarks of Google LLC. Kubernetes® is the registered trademark of The Linux Foundation in the United States and/or other countries. Linux® is the registered trademark of Linus Torvalds in the U.S. and other countries. Microsoft®, Microsoft Edge™, and Windows® are either registered trademarks or trademarks of Microsoft Corporation in the United States and/or other countries. Mozilla and Firefox are trademarks of the Mozilla Foundation in the U.S. and other countries. SAP HANA® is the trademark or registered trademark of SAP SE or its affiliates in Germany and in several other countries. Disclaimer The details and descriptions contained in this document are believed to have been accurate and up to date at the time the document was written. The information contained in this document is subject to change without notice.
    [Show full text]
  • SAP の本番環境に Google Cloud Platform を 選ぶ理由
    SAP の本番環境に Google Cloud Platformを 選ぶ理由 Google Cloud Japan SAP スペシャリスト 井上 和英(Kazuhide Inoue) Confidential & Proprietary Proprietary + Confidential 井上 和英 自己紹介 Kazuhide Inoue カスタマーエンジニア SAP Specialist Google Cloud Japan [email protected] < 略歴 > ● GCP で IM Specialist(SAP)を担当 ● パブリックク ラウドベンダーで SAP 担当を歴任 https://twitter.com/inkz1101 ● SAP Japan で テクノロジー コンサルタントとして導入 PJ 参画 ● SIer で業務系システムの開発プロジェクトに参画 https://www.facebook.com/kazuhide.inoue.129 ● https://www.linkedin.com/in/kazuhide-inoue-4a198574/ < 趣味 > ● ロードバイク ● 音楽 Proprietary + Confidential 本セッションでお伝えしたいこと SAP 本番環境に求められる要件と Google Cloud での対応 | 次のステップに向けて Proprietary + Confidential SAP 本番環境に 求められる要件と Google Cloud で の対応 01 + SAP 本番環境に求められる要件 東阪にサイトを設けたい。 拡張性 グローバル事業なので、海外からの利用も・・・。 とりあえず S/4HANA を試したい。 インフラのメンテナンスやパッチ適用に引きづられたくな 安定性 い。 5 年後の利用状況がわからない・・・。 柔軟性 容量に縛られないインフラが欲しい。 SAP インフラのコストは最小限に押さえたい。 コスト効率性 時期性のあるインフラ利用に対応したい。 Proprietary + Confidential Google Cloud のインフラについて Google Cloud Current region Future region Edge point Network Platform with 3 zones with 3 zones of presence Regions, PoPs, and network GCP 大阪 GCP 東京 a a Finland Netherlands b c b c Warsaw London Frankfurt Montréal Belgium Oregon Iowa* Zurich Salt Lake City N. Virginia Seoul Las Vegas Tokyo Los Angeles S. Carolina Osaka Taiwan Hong Kong Mumbai Singapore Jakarta São Paulo Sydney Google Cloud Current region Future region Edge point Platform with 3 zones with 3 zones of presence Regions and PoPs *Exception: region has 4 zones. Google Compute Engine(GCE)について ● 仮想マシン(VM)のサービス ● CPU やメモリなどのリソースを柔軟に変更 可能 ● ライブ マイグレーションを標準実装。
    [Show full text]
  • Chromebook Basics for Parents
    CHROMEBOOK BASICS FOR PARENTS What is a Chromebook? A Chromebook is different from a traditional laptop. Chromebooks use Google’s operating system, Chrome OS, instead of using the Windows or macOS operating systems. These machines are designed to be used primarily while connected to the Internet, with most applications and documents living in the “cloud.” Files can be downloaded and store on the Chromebook, but storage is minimal (16 GB for Dell and 32 GB for Acer Chromebooks). The Chromebooks have 4 GB of RAM. Manage vs Non-Manage Chromebooks A managed Chromebook is set up and maintained centrally by Why Chromebooks for the school District. Managed Chromebooks have features and Students? restrictions set up by the District. For instance, District 205 has Instant On web filtering enabled and has Wi-Fi Information configured. The District can also push or restrict certain apps or extensions. No Software Updates A non-managed Chromebook is not controlled in any way. It is No Viruses a personal device with no pre-set restrictions. Long Batter Life (9-10 hours) Note: District 205 will “release” the Chromebooks to students Light Weight who leave the District (i.e. graduation) to keep it as a Available Apps non-managed Chromebook. Files stored on the Google Account will be deleted. Integrated with Google tools 125 S. Prospect Avenue, Elmhurst, IL 60126 Start Using Computers, (630) 279-8696 ● elmhurstpubliclibrary.org Tablets, and Internet GETTING STARTED Signing In Just like a normal laptop, once you turn on your Chromebook vs Chrome vs Google Chromebook, it will ask you to sign into an Tools account.
    [Show full text]
  • Understanding Alphabet and Google, 2017
    This research note is restricted to the personal use of [email protected]. Understanding Alphabet and Google, 2017 Published: 24 February 2017 ID: G00297707 Analyst(s): Tom Austin, David Mitchell Smith, Yefim V. Natis, Isabelle Durand, Ray Valdes, Bettina Tratz-Ryan, Roberta Cozza, Daniel O'Connell, Lydia Leong, Jeffrey Mann, Andrew Frank, Brian Blau, Chris Silva, Mark Hung, Adam Woodyer, Matthew W. Cain, Steve Riley, Martin Reynolds, Whit Andrews, Alexander Linden, David Yockelson, Joe Mariano Google's size, market differentiation, rapid pace of innovation and ambitions can complicate fully understanding the vendor and its fit to current digital business needs. CIOs and IT leaders can use this report to explore in detail selected topics from the Gartner Vendor Rating. Key Findings ■ Two outcomes are apparent more than a year after the creation of the Alphabet-Google structure: Google is beginning to show increased momentum and has made significant investments in its enterprise offerings (most of its 2016 acquisitions were focused on this); and it is applying more discipline in Alphabet's "Other Bets." ■ Google is flourishing despite challenging external market factors: adverse publicity, competitors, government regulators and law enforcement. ■ Google values data, encourages bold investments in long-term horizons, pivots plans based on results in near real time, and reveres user-oriented engineering excellence. ■ Google is fully committed to 100% cloud-based and web-scale infrastructure, massive scaling, the maximum rate of change, and stream-lined business processes for itself and its customers. Recommendations CIOs and IT leaders managing vendor risk and performance should: ■ Plan for a long-term strategic relationship with Google based on an assumption that "what you see is what you get." Major vendor changes to core culture and fundamental operating principles in response to customer requests usually come slowly, if at all.
    [Show full text]