<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>– KMS</title><link>https://changelog.exoscale.com/tags/kms/</link><description>Recent content in KMS on</description><generator>Hugo -- gohugo.io</generator><language>en</language><lastBuildDate>Wed, 07 Oct 2026 05:00:00 +0000</lastBuildDate><atom:link href="https://changelog.exoscale.com/tags/kms/rss.xml" rel="self" type="application/rss+xml"/><item><title>KMS now supports asymmetric encryption and digital signatures</title><link>https://changelog.exoscale.com/kms-asymmetric-cryptography-and-digital-signatures/</link><pubDate>Wed, 07 Oct 2026 05:00:00 +0000</pubDate><guid>https://changelog.exoscale.com/kms-asymmetric-cryptography-and-digital-signatures/</guid><description>
&lt;p&gt;Exoscale Key Management Service (KMS) now supports asymmetric keys for encryption and digital signatures. They&amp;rsquo;re available through the API, CLI, Portal and SDKs.&lt;/p&gt;
&lt;p&gt;&lt;img src="https://changelog.exoscale.com/kms-asymmetric-cryptography-and-digital-signatures/kms-create-asymmetric-key.png" alt="Creating an asymmetric signing key in the Exoscale Portal" loading="lazy" /&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What’s new&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;RSA encryption:&lt;/strong&gt; Create RSA-3072 or RSA-4096 key pairs and export the public key to whoever needs to send you data. They can encrypt without a KMS account, and decryption happens only inside KMS, with the private key never leaving it.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Digital signatures:&lt;/strong&gt; Sign data with RSA-PSS, ECDSA, Ed25519 or ML-DSA keys. Signing always happens in KMS. You can verify signatures in KMS as well, or export the public key and verify with your own tools, offline if needed.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Post-quantum signatures:&lt;/strong&gt; ML-DSA-65 and ML-DSA-87 implement FIPS 204, the Module-Lattice-Based Digital Signature standard NIST published in 2024. Unlike RSA and ECDSA, ML-DSA is designed to resist forgery by future quantum computers. That makes it a fit for signatures that must remain verifiable for many years. ML-DSA-65 targets NIST security category 3, and ML-DSA-87 targets category 5.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;These additions let you use KMS for application encryption, signing workflows, and integrations that require public-key cryptography, without exposing private key material.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://community.exoscale.com/product/security/kms/how-to/sign-verify/"target="_blank" rel="noopener"&gt;See how to sign and verify data with KMS →&lt;/a&gt;&lt;/p&gt;</description></item></channel></rss>