when performing manual KMS key rotation using customer generated KMS key material, and following the procedure as per documentation, how is the old information decrypted (ie the info that was encrypted with the old CMK) , if you have deleted the old key and changed to new generated CMK?
When you rotate keys the old key is retained to decrypt data encrypted using that key. New data is encrypted using the new material.
When you rotate the keys, the old key is not deleted hence the old data can still be decrypted. If you delete the old key, you will not be able to decrypt the data that was encrypted with the old key