JSCAPE
  • Products
    • Managed File Transfer
    • JSCAPE SaaS
    • MFT Gateway
    • MFT Monitor
    • All Products
  • Solutions
    • All Solutions
    • Secure File Transfer
    • AS2 Server Software
    • File Synchronization
    • Reverse Proxy
    • Compliance
    • DMZ Streaming
  • Pricing
  • Company
    • Blog
    • Company
    • Contact Us
    • Clients
    • Case Studies
    • Testimonials
    • Certifications
  • Support
    • Help Desk
    • Documentation
    • Customer Downloads
Get a demo

Using AWS KMS to encrypt files you upload to your s3 trading partner

Words by

John Carl Villanueva

Files you upload to an Amazon S3 trading partner through JSCAPE MFT Server are normally stored in plaintext. If you want to encrypt those files to minimize the risk of a data breach, one way to do that is by using the AWS Key Management Service or AWS KMS. We’ll show you how to use…

Published in:

Blog

/

Business Process Automation, JSCAPE MFT, Managed File Transfer, Triggers, Tutorials

Files you upload to an Amazon S3 trading partner through JSCAPE MFT Server are normally stored in plaintext. If you want to encrypt those files to minimize the risk of a data breach, one way to do that is by using the AWS Key Management Service or AWS KMS. We’ll show you how to use this particular service in this post.

Watch the video

Would you prefer to watch a video version of this tutorial instead? You can play the video below. Otherwise, just skip it if you wish to continue reading.

Note that there are costs associated with the AWS KMS service, so I suggest you read this page on the AWS website first.

Alright. The first thing you need to do is to create a customer master key or CMK. You can create this key through either the AWS KMS API or the AWS Management Console. We’ll be using the latter. Login to your AWS Management Console and go to the Key Management Service. If you haven’t used that service yet, the easiest way to find it is by simply typing it into the search box as shown in the screenshot below.

Using AWS KMS To Encrypt Files You Upload To Your S3 Trading Partner - kms service

Pay attention to the region displayed at the upper-right corner of the screen. While you may change that region, just make sure it’s the same region you select in your JSCAPE MFT Server Amazon S3 trading partner object.

Click the Create key button to start creating your CMK. We’ll just be creating a very basic CMK, so if you want to know more about all the relevant concepts and advanced settings, I suggest you read the AWS KMS Developer Guide.

Using AWS KMS To Encrypt Files You Upload To Your S3 Trading Partner - create key-1

Select Symmetric and then click Next.

Recommended read: Symmetric vs Asymmetric Encryption

Using AWS KMS To Encrypt Files You Upload To Your S3 Trading Partner - create symmetric key

Enter an alias for this key. This is just an arbitrary human-friendly name you’ll be using to refer to this key here in the AWS environment and in your JSCAPE MFT Server Amazon S3 trading partner object.

You may also add a short description if you want. Click Next to proceed.

Using AWS KMS To Encrypt Files You Upload To Your S3 Trading Partner - kms key alias

Next, select the IAM user who you want to administer this key. In my case, I’m just using my own user account.

Using AWS KMS To Encrypt Files You Upload To Your S3 Trading Partner - choose IAM user

After that, select the IAM user who you want to use this CMK in cryptographic operations. Again, I’m just choosing my own user account.

Click Next to proceed.

Using AWS KMS To Encrypt Files You Upload To Your S3 Trading Partner - cmk IAM user

Lastly, click Finish to finalize the CMK creation process.

Using AWS KMS To Encrypt Files You Upload To Your S3 Trading Partner - create key finish

You should then see your newly created customer master key among your list of CMKs.

Want to try these steps in your own environment? Request a risk-free trial of JSCAPE here.

Using AWS KMS To Encrypt Files You Upload To Your S3 Trading Partner - newly created key

Now that you have your CMK ready, the next step is to assign that key to an Amazon S3 bucket. Go to the AWS S3 service

AWS KMS To Encrypt Files You Upload To Your S3 - s3 service

… and then click the bucket whose data you want to encrypt with AWS KMS.

AWS KMS To Encrypt Files You Upload To Your S3 - s3 buckets

Navigate to the Default encryption section and then click the text at the bottom. Normally, that would be AES-256.

AWS KMS To Encrypt Files You Upload To Your S3 - s3 bucket properties

When the Default encryption dialog box pops up, select the AWS-KMS option and then click the alias of the CMK you created earlier. In my case, that would be ‘jcv-testkey‘.

Click Save to proceed.

AWS KMS To Encrypt Files You Upload To Your S3 - select default encryption

The text at the bottom of the Default encryption section should now display AWS-KMS instead of AES-256.

AWS KMS To Encrypt Files You Upload To Your S3 - aws kms default encryption

That’s all you need to do on the AWS Management Console. You may now proceed to your JSCAPE MFT Server instance and edit your Amazon S3 trading partner. In my case, the name of my S3 trading partner is ‘tp-s3’.

AWS KMS To Encrypt Files You Upload To Your S3 - edit s3 trading partner

Once you’re inside your Amazon S3 trading partner parameters dialog, scroll down to the Authentication section. Make sure the Access Key ID of this S3 trading partner is the access key ID of the username you used in creating the CMK.

Tick the Use encryption check box and then select the region that matches the region displayed when you created your CMK. In my case, that would be US East (Ohio). After that, select the AWS-KMS option and expand the adjacent drop-down list. Click the alias of the CMK you created earlier and then click OK to apply the changes.

AWS KMS To Encrypt Files You Upload To Your S3 - use aws-kms encryption-1

That’s all there is to it.

Before we end, let me just show you what happens when you upload a file to your AWS-KMS-protected Amazon S3 bucket from JSCAPE MFT Server.

What I have here is a trigger that uploads a file to my Amazon S3 bucket.

AWS KMS To Encrypt Files You Upload To Your S3 - trigger trading partner file upload

So, as you can see, the Partner setting is set to tp-s3, which is the name of my Amazon S3 trading partner object. The file this trigger is configured to upload is named file01.txt, and it’s going to be uploaded to the folder named ‘folder1’ under the S3 bucket named ‘jscapejohn’.

AWS KMS To Encrypt Files You Upload To Your S3 - trigger trading partner file upload action

So, if I run this trigger…

AWS KMS To Encrypt Files You Upload To Your S3 - trigger trading partner file upload run

… and check inside the S3 bucket folder named folder1 through the AWS Management Console, I should see the newly uploaded file named file01.txt. If I click on that file and check its properties, I see that it has indeed been encrypted with AWS-KMS encryption.

AWS KMS To Encrypt Files You Upload To Your S3 - uploaded file encrypted with aws-kms

That’s it. Now you know how to use AWS KMS to encrypt files uploaded to your S3 trading partner using JSCAPE MFT Server.

Get started

Get a JSCAPE free trial at no obligation. > Here’s the link < to request your trial experience.

Related content

How To Copy Data From Azure To AWS S3 | JSCAPE

How to Download Newly Added Files from an AWS S3 Folder

How To Schedule Automated File Uploads From Your Server To Box Cloud Storage

How To Use Amazon S3 As The File Storage System of Your MFT Server

Amazon S3 vs Local Storage – Where Should You Store Files Uploaded to Your File Transfer Server?

Easy To Deploy, Easy To Administer, Easy To Manage

Ready to see how JSCAPE makes managed file transfer so much simpler? Schedule your demo now.

Request a demo

Popular Articles

View more by

JSCAPE
  •  
    1–2 minutes
    23/09/2025

    JSCAPE by Redwood, version 2025.3: New UI continues to make a splash

    Dive back into JSCAPE by Redwood with version 2025.3, bringing more modern UI updates to make using and navigating JSCAPE more intuitive. 

    Read article

  •  
    1–2 minutes
    19/08/2025

    Weathering the economic storm: Expert support is your enterprise file transfer system’s lifeline

    The global economic landscape can be described by one word: “uncertain”. Lingering effects from the 2020 pandemic, combined with new waves of international tariffs throughout 2025, have…

    Read article

  •  
    1–2 minutes
    30/07/2025

    Escape the grip: Why flexible MFT is key to enterprise agility

    Break free from costly vendor lock-in Let’s be blunt: some MFT vendors have built product suites that are less about true partnership and more about proprietary siloing.…

    Read article

  •  
    1–2 minutes
    23/07/2025

    Avoid downtime and threat actors: Getting the best of both worlds in MFT

    For enterprise organizations relying on managed file transfer (MFT) solutions, cybersecurity often feels like an arms race. The need to patch MFT software vulnerabilities to prevent breaches…

    Read article

Related Content

Read more about

JSCAPE MFT
  •  
    1–2 minutes
    30/07/2025

    Escape the grip: Why flexible MFT is key to enterprise agility

    Break free from costly vendor lock-in Let’s be blunt: some MFT vendors have built product suites that are less about true partnership and more about proprietary siloing.…

    Read article

  •  
    1–2 minutes
    03/07/2025

    Consolidate, deploy and thrive: JSCAPE’s formula for MFT success in uncertain times

    Global enterprises today are navigating a landscape marked by significant economic volatility. Fluctuating markets, shifting trade policies and persistent economic uncertainty are compelling enterprise organizations to reevaluate…

    Read article

  •  
    1–2 minutes
    31/03/2025

    SFTP vs. FTPS: Which file transfer software is best for business use?

    What is SFTP? SFTP is a file transfer protocol that’s normally packaged with Secure Shell (SSH), the network protocol most IT administrators use to access and manage…

    Read article

  •  
    1–2 minutes
    25/03/2025

    EDI integration with trading partners: 6 best practices

    Many large companies with high-volume transactions, especially those involved in e-commerce, manufacturing and retail supply chains, have long migrated from manual processes to Electronic Data Interchange (EDI).…

    Read article

Company

  • About Us
  • Contact Us
  • Clients
  • Case Studies
  • Testimonials
  • Privacy Policy
  • Certifications

Resources

  • Managed File Transfer
  • Secure File Transfer
  • Secure FTP Server
  • AS2 Server
  • Reverse Proxy
  • File Upload Processing
  • What Is An AS2 Server?

Support

  • Help Desk
  • Documentation
  • Customer Downloads
JSCAPE

Copyright © 2025 JSCAPE

  • Privacy Policy
  • Cookie Settings