kmsKeyId
The ID of the KMS key that you want to use to protect the encrypted file system. This parameter is required only if you want to use a non-default KMS key. If this parameter is not specified, the default KMS key for Amazon EFS is used. You can specify a KMS key ID using the following formats:
Key ID - A unique identifier of the key, for example
1234abcd-12ab-34cd-56ef-1234567890ab
.ARN - An Amazon Resource Name (ARN) for the key, for example
arn:aws:kms:us-west-2:111122223333:key/1234abcd-12ab-34cd-56ef-1234567890ab
.Key alias - A previously created display name for a key, for example
alias/projectKey1
.Key alias ARN - An ARN for a key alias, for example
arn:aws:kms:us-west-2:444455556666:alias/projectKey1
.
If you use KmsKeyId
, you must set the CreateFileSystemRequest$Encrypted parameter to true.
EFS accepts only symmetric KMS keys. You cannot use asymmetric KMS keys with Amazon EFS file systems.