Key Rotation is the process of creating a new version of an encryption key while retaining older key versions for decrypting existing data.
When a new key version is created in ESKM, the previously created key versions are retained and continue to be used for decrypting existing data. The newly created key version becomes the current (default) key for encrypting new data.
This capability enables the creation of a new version of the key on-demand for the purposes of compliance or suspected compromise without changing the key ID or disrupting active cloud applications.
To rotate a key in Azure Cloud
-
After creating a new version of the encryption key, go to the Actions column for the key.
Upload key
-
Select Upload to upload the new key version to the Azure Cloud console.
For detailed steps, refer to Upload Key from ESKM to Azure Cloud.
Auto-Key Rotation
Automatic Key Rotation enables scheduled creation of new key versions without manual intervention. Based on the configured rotation policy, ESKM automatically generates a new version of the selected key and uploads it to Azure Key Vault. Older key versions are retained and continue to be available for decrypting previously encrypted data.
Auto rotation
Note: Automatic Rotation can be configured during key creation or enabled later by editing an existing key. Administrators can modify the rotation settings by enabling/disabling Auto Rotation for the desired key.