Updated on 2022-02-22 GMT+08:00

Scheduling the Deletion of One or Multiple CMKs

Scenario

This section describes how to use the management console to schedule the deletion of one or multiple unwanted CMKs.

If deletion is scheduled for a CMK, the deletion will not take effect immediately. Instead, it will take effect after a waiting period of 7 to 1096 days. Before the specified deletion date, you can cancel the deletion if you want to use the CMK. Once the scheduled deletion has taken effect, the CMK will be deleted permanently and you will not be able to decrypt data encrypted by it. Therefore, you are advised to exercise caution when performing this operation.

Before deleting the CMK, confirm that it is not in use and will not be used.

Default Master Keys created by KMS cannot be scheduled for deletion.

Prerequisites

  • You have obtained an account and its password for logging in to the management console.
  • The CMK you want to schedule deletion for is in Enabled or Disabled status.

Procedure

  1. Log in to the management console.
  2. Choose Security > Key Management Service. The Key Management Service page is displayed.
  3. In the row containing the desired CMK, click Delete.

    Figure 1 Scheduling the deletion for one CMK

  4. In the dialog box that is displayed, enter the number of days after which you want the deletion to take effect.

    Figure 2 Scheduling a deletion time

  5. Click Yes to schedule the deletion.

    To delete multiple CMKs at a time, select them and click Delete in the upper left corner of the list.