In this guide, you can learn how to manage your encryption keys with a Key Management System (KMS) in your application.
Overview
This procedure shows you how to rotate encryption keys for Queryable Encryption.
Tip
Rotate and Rewrap
Rotating DEKs consists of rewrapping them with a new Customer Master Key. This guide uses the terms "rotate" and "rewrap" interchangeably.
After completing this guide, you can rotate your Customer Master Key (CMK) on your Key Management System, and then rewrap existing DEKs in your Key Vault collection with your new CMK.
Warning
As you rotate keys, confirm that they aren't used to encrypt any keys or data before deleting them. If you delete a DEK, all fields encrypted with that DEK become permanently unreadable. If you delete a CMK, all fields encrypted with a DEK using that CMK become permanently unreadable.
Related Information
For a detailed explanation of the concepts included in this procedure, refer to the topics below.
To learn more about keys and key vaults, see Encryption Keys and Key Vaults. To view a list of supported KMS providers, see the KMS Providers page.
For tutorials detailing how to set up a Queryable Encryption enabled application with each of the supported KMS providers, see Overview: Enable Queryable Encryption.
Procedure
Your DEKs themselves are left unchanged after rewrapping them with the new CMK. The key rotation process is seamless, and does not interrupt your application.