Auto-Key Rotation

Automatic Key Rotation enables scheduled creation of new key versions without manual intervention. Based on the configured rotation policy, ESKM automatically generates a new version of the selected key and uploads it to AWS Key Management Service. Older key versions are retained and continue to be available for decrypting previously encrypted data.

 

image-20260709-115659.png


Auto Rotation

Automatic Rotation can be configured during key creation or enabled later by editing an existing key. Administrators can modify the rotation settings by enabling/disabling Auto Rotation for the desired key.