Scenarios
To further enhance the security of ciphertext storage, Tencent Cloud KMS provides users with transparent key rotation capability, which can be used to refresh stored ciphertext.
The key rotation for root keys (CMKs) provides users with transparent key rotation capability. After a CMK is rotated, user operations are not affected, and ciphertext encrypted before the rotation remains compatible. Additionally, the ReEncrypt API is provided to refresh ciphertext. This document describes how to enable key rotation via the console. Operation Steps
1. Log in to the KMS (Compliant) console. In the left sidebar, click Key Management > Root Key. 2. On the Root Key Management page, select the root key for which you want to set up key rotation. In the Operation column, choose More > Set rotation policy.
Attention:
By default, key rotation is disabled. You can configure whether to enable it. After it is enabled, the CMK is rotated once a year.
3. In the Set Rotation Policy window, you can choose to enable or disable key rotation. Click Enable to set the rotation time.