# How to configure server-side encryption

Source: https://docs.quake.ai/docs/object/how-to/configure-server-side-encryption
Markdown: https://docs.quake.ai/docs/object/how-to/configure-server-side-encryption.md

---

# How to configure server-side encryption

Use Server-Side Encryption with Customer-Provided Keys (SSE-C) to encrypt an object with a 256-bit key that you manage. Quake AI Object Storage applies AES-256 encryption and requires the same key for later read and metadata requests.



Keep a recoverable copy of each encryption key. If you lose a key, you lose access to the objects encrypted with it. Do not commit keys to source control or include them in URLs.





SSE-C uses the S3-compatible API. The OpenStack Swift API does not provide a customer-key encryption path on this gateway.



<PrerequisiteBlock methods={["cli"]}>

- An existing object storage bucket
- [S3 credentials](/docs/object/how-to/create-s3-credentials) with access to the bucket
- AWS CLI configured with those credentials
- OpenSSL for generating a key

</PrerequisiteBlock>

## Set the object details and generate a key

Set variables for your bucket, local file, and object key. Generate a 256-bit, Base64-encoded encryption key:

```bash
export BUCKET_NAME="YOUR_BUCKET_NAME"
export SOURCE_FILE="PATH_TO_YOUR_FILE"
export OBJECT_KEY="YOUR_OBJECT_KEY"
export SSE_C_KEY="$(openssl rand -base64 32)"
```

Store `SSE_C_KEY` in your key-management system before uploading the object. The shell variable lasts only for the current shell session.

## Upload the encrypted object

<MethodTabs>
<Method label="CLI">

Upload the object with the SSE-C algorithm and key:

```bash
aws s3api put-object \
  --bucket "$BUCKET_NAME" \
  --key "$OBJECT_KEY" \
  --body "$SOURCE_FILE" \
  --sse-customer-algorithm AES256 \
  --sse-customer-key "$SSE_C_KEY" \
  --endpoint-url "https://object.us-east-1.rumble.cloud"
```

A successful response includes `SSECustomerAlgorithm` set to `AES256` and an `SSECustomerKeyMD5` value.

</Method>
</MethodTabs>

## Verify the encrypted object

Provide the same algorithm and key when you request object metadata:

```bash
aws s3api head-object \
  --bucket "$BUCKET_NAME" \
  --key "$OBJECT_KEY" \
  --sse-customer-algorithm AES256 \
  --sse-customer-key "$SSE_C_KEY" \
  --endpoint-url "https://object.us-east-1.rumble.cloud"
```

The response includes the object's content length, content type, last-modified time, ETag, and customer-key MD5. The ETag for an SSE-C object is not an MD5 hash of the object data.

The gateway returns `400 Bad Request` if a `head-object` request omits the SSE-C headers. A `get-object` request without those headers returns `InvalidArgument`.

## Download the encrypted object

Provide the key with each download request:

```bash
aws s3api get-object \
  --bucket "$BUCKET_NAME" \
  --key "$OBJECT_KEY" \
  --sse-customer-algorithm AES256 \
  --sse-customer-key "$SSE_C_KEY" \
  --endpoint-url "https://object.us-east-1.rumble.cloud" \
  "DECRYPTED_OUTPUT_FILE"
```

Compare the downloaded file with the source:

```bash
cmp "$SOURCE_FILE" "DECRYPTED_OUTPUT_FILE"
```

`cmp` exits without output when the files match.

## Delete an encrypted object

Deleting an SSE-C object requires permission to delete the object. It does not require the encryption key:

```bash
aws s3api delete-object \
  --bucket "$BUCKET_NAME" \
  --key "$OBJECT_KEY" \
  --endpoint-url "https://object.us-east-1.rumble.cloud"
```

Restrict delete permissions separately from access to the encryption key. [Enable object versioning](/docs/object/how-to/enable-versioning) if you need to recover an object after an accidental delete.

## Troubleshoot SSE-C requests

- **The AWS CLI reports an unknown option:** Use `--sse-customer-algorithm` and `--sse-customer-key`. The longer `--server-side-encryption-customer-*` option names are not valid AWS CLI flags.
- **The gateway rejects the key:** Generate a 256-bit, Base64-encoded key with `openssl rand -base64 32`.
- **A read or metadata request fails:** Provide the algorithm and key used for the upload.
- **The downloaded file does not match:** Confirm that the request targets the correct bucket and object key, then compare it with `cmp`.
- **The request uses HTTP:** Change the endpoint to HTTPS. SSE-C requests require an encrypted connection.

## Next steps

- [Enable object versioning](/docs/object/how-to/enable-versioning)
- [Grant access to object storage](/docs/object/how-to/grant-access-control)
- [Access an uploaded object](/docs/object/how-to/access-uploaded-file)
