Certified Security - Specialty

Sign Up Free or Log In to participate!

Does Amazon perform key rotation for EBS encrypted volumes?

1 Answers

EBS uses KMS for volume encryption

http://docs.aws.amazon.com/kms/latest/developerguide/services-ebs.html

So the same key rotation rules apply as with any other KMS service. Whether its a default (AWS supplied) CMK or a customer supplied one. 

"You can choose to have KMS automatically rotate keys generated by KMS on your behalf every year. Automatic key rotation is not supported for imported keys. If you choose to import keys to KMS, you can manually rotate them whenever you want"

https://d0.awsstatic.com/whitepapers/KMS-Cryptographic-Details.pdf

Sign In
Welcome Back!

Psst…this one if you’ve been moved to ACG!

Get Started
Who’s going to be learning?