Updated on 2023-01-31 GMT+08:00

Enabling Key Rotation

This section describes how to enable rotation for a CMK on the KMS console.

By default, automatic key rotation is disabled for a CMK. Every time you enable key rotation, KMS automatically rotates CMKs based on the rotation period you set.

Prerequisites

  • The CMK is enabled.
  • The Origin of the CMK is KMS.

Constraints

A disabled CMK is never rotated, even if rotation is enabled for it.

KMS resumes rotation when this CMK is enabled. If you enable this CMK after one rotation period has passed, KMS will rotate it within 24 hours.

Procedure

  1. Log in to the management console.
  2. Click in the upper left corner of the management console and select a region or project.
  3. Click . Choose Security & Compliance > Data Encryption Workshop.
  1. Click the alias of the desired CMK to view its details.

    Figure 1 CMK details

  2. Click the Rotation Policy tab. The rotation switch is displayed.

    Figure 2 CMK rotation

  3. Click to enable key rotation.
  4. Configure the rotation period and click OK, as shown in Figure 3. For more information, see Table 1.

    Figure 3 Enabling key rotation
    Table 1 Key rotation parameters

    Parameter

    Description

    CMK rotation

    Rotation switch. The default status is .

    : disabled

    : enabled

    After rotation is enabled, the CMK will be rotated based on your set period.

    NOTE:

    A disabled CMK is never rotated, even if rotation is enabled for it.

    KMS resumes rotation when this CMK is enabled. If you enable this CMK after one rotation period has passed, KMS will rotate it within 24 hours.

    Rotation Period (day)

    Rotation period (day). The value is an integer ranging from 30 to 365. The default value is 365.

    Configure the period based on how often a CMK is used. If it is frequently used, configure a short period; otherwise, set a long one.

  5. Check rotation details, as shown in the following figure.

    Figure 4 CMK rotation details

    You can click to change the rotation period. After the period is changed, KMS rotates the CMK by the new period.