Skip to content

Commit ddbc951

Browse files
mbevc1claude[bot]
andauthored
fix: update administration/authentication/dedicated_instance_kms_keys.md
Co-authored-by: claude[bot] <209825114+claude[bot]@users.noreply.github.com>
1 parent 45225f8 commit ddbc951

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

‎administration/authentication/dedicated_instance_kms_keys.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@ A member of the Kosli Customer Success team will give you:
2323

2424
## Choose the key shape
2525

26-
AWS only permits **multi-region KMS keys** where the key material originates in KMS itself.
26+
AWS does not permit **multi-region KMS keys** whose key material lives in a custom key store.
2727

2828
- If your cryptographic policy allows KMS-generated key material, create **one multi-region key** in the primary region and replicate it into the secondary region. This is the path described below.
2929
- If your policy requires an [AWS CloudHSM key store](https://docs.aws.amazon.com/kms/latest/developerguide/keystore-cloudhsm.html) or an external key store for key material, create **two single-region keys** — one in each region. See [Single-region keys](#single-region-keys) for the differences.

0 commit comments

Comments
 (0)