Certified Security - Specialty

Sign Up Free or Log In to participate!

when manual KMS key rotation using customer generated KMS key material, and following the procedure as per documentation, how is the old information decrypted (ie the info that was encrypted with the old CMK) , if you have changed to new generated CMK?

when performing manual KMS key rotation using customer generated KMS key material, and following the procedure as per documentation, how is the old information decrypted (ie the info that was encrypted with the old CMK) , if you have deleted the old key and changed to new generated CMK?

2 Answers

Hi Alanm,

When you rotate keys the old key is retained to decrypt data encrypted using that key. New data is encrypted using the new material.

Chatz

Hi Alanm,

When you rotate the keys, the old key is not deleted hence the old data can still be decrypted. If you delete the old key, you will not be able to decrypt the data that was encrypted with the old key

Fidelis

Sign In
Welcome Back!

Psst…this one if you’ve been moved to ACG!

Get Started
Who’s going to be learning?