Updated on 2024-10-21 GMT+08:00

Rotating Encryption Keys

If you have enabled the Encrypt DataStore function in Advanced Settings during cluster creation, you can rotate the encryption keys for the cluster after the cluster is created successfully. When a normal cluster is converted to an encrypted cluster, you can rotate the encryption key for the cluster. Each key rotation will update the CEK once. During the key rotation, the cluster is still in Available status.

Rotating Encryption Keys for GaussDB(DWS) Clusters

  1. Log in to the GaussDB(DWS) console.
  2. In the navigation tree on the left, choose Clusters > Dedicated Clusters.
  3. In the cluster list, find the target cluster and click the cluster name. The Cluster Information page is displayed.
  4. In the Data Encryption Information area, click Key Rotation.
  5. In the dialog box that is displayed, click Yes.