---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Generate a ServiceNow cryptographic key

# Generate a ServiceNow cryptographic key {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

Follow this procedure to upload and configure a ServiceNow
cryptographic key to encrypt sensitive data.

## Vorbereitungen

Role required: sn_kmf.cryptographic_manager

## Warum und wann dieser Vorgang ausgeführt wird

Cryptographic managers have the choice to use ServiceNow
supplied keys or their own customer-supplied keys (CSK) for encryption on the ServiceNow AI Platform with Field Encryption Enterprise. For information on
CSK, see [Configure properties for customer-supplied keys](https://servicenow-prod.fluidtopics.net/Wg7gwmbhwjqas7ygpSOHmQ "If the Field Encryption Enterprise plugin is enabled, you can use system properties to define key padding, ephemeral key pair size, and a key validity period of your customer-supplied keys.").

## Prozedur

1. Set field encryption settings to use ServiceNow Generated Keys.  
   See [Configure field encryption settings to select key type](https://servicenow-prod.fluidtopics.net/ovSySxDFj9lpVnXICaHrDw "Configure your field encryption settings to use ServiceNow supplied keys or your own customer-supplied keys (CSK) for encryption on the ServiceNow AI Platform.") for details.
2. Navigate to Key ManagementCryptographic ModulesAll.
3. Select the corresponding cryptographic module to open the Cryptographic Module details page.
4. Select the row for the key alias entry on the Crypto Specifications tab.  
   If a key hasn't yet been generated, the key alias field is empty.
5. Select Next to navigate to the Key Origin tab of the Crypto Specification components.  
   The Lifecycle Definition tab displays along with the Key Lifecycle table and can be reviewed or edited. See [Configure key lifecycle states](https://servicenow-prod.fluidtopics.net/NVIDPtYNGu5nP4Wd3oW4Tw "After you have created a cryptographic specification, you can configure the lifecycle actions for the keys in your instance.") for details.
6. Select Servicenow in the Origin field.  
   This field varies based on the field encryption settings from Step 1 and the algorithm selected. To use an imported key, see [Import the wrapping / unwrapping key pair](https://servicenow-prod.fluidtopics.net/LJgZg8VNdUMfFPJrzbTVog#import-key-webservice "Configure Key Management Framework import settings before importing a key."). See [Configure properties for customer-supplied keys](https://servicenow-prod.fluidtopics.net/Wg7gwmbhwjqas7ygpSOHmQ "If the Field Encryption Enterprise plugin is enabled, you can use system properties to define key padding, ephemeral key pair size, and a key validity period of your customer-supplied keys.") if you're using your own key.
7. Enter a friendly name for the Key alias.
8. Select Next to move to the Key Creation tab.
9. Select Generate Key.  
   After you generate the key, the Cryptographic Module form reloads displaying the cryptographic specification.
10. Select the Module Keys tab to view the keys.  
    Secure information for the key is stored on the Module Keys tab along with the number of keys that exist for the cryptographic specification.
11. Select a key to perform key management actions.  
    See [Key management actions](https://servicenow-prod.fluidtopics.net/NGmgWoxP2Pw2QP6mkUZUOQ "One of the core features of KMF is to provide the capability  to manage  keys, such as revoking or rotating keys.  KMF properly secures sensitive data with the most up-to-date encryption materials and life cycle operations.") for details.

