tencent cloud

DokumentasiKey Management Service

Cloud Product Key Rotation

Download
Mode fokus
Ukuran font
Terakhir diperbarui: 2026-07-24 11:55:52
Diterjemahkan oleh AI
KMS provides you with the capability for transparent rotation of cloud product keys. After a cloud product key is created, its automatic rotation is enabled by default. You can also manually disable automatic rotation when needed, or manually trigger an immediate rotation. Key rotation does not affect your business and remains compatible with data encrypted before the rotation. This document describes how to manage cloud product key rotation through the console.

Viewing Cloud Product Key Rotation Status

1. Log in to the KMS (Compliant) console. In the left sidebar, choose Key Management > Cloud Product root key.
2. On the Cloud Product Key Management page, view the status in the Key Rotation column of the key list.
It is displayed as Enabled: rotation is enabled for this key.
It is displayed as Disabled: rotation is not enabled for this key.
3. To view key details, click the Key ID /Name of the target key to go to the key details page.
4. On the key details page, details such as the key name, key ID, region, rotation status, last rotation time, next rotation time, creator, creation time, and description of the key are displayed.

Setting Cloud Product Key Rotation Policies

After a cloud product key is created, its automatic rotation is enabled by default. When you no longer need automatic rotation, you can disable the rotation feature. After it is disabled, you can also re-enable it. By setting a rotation policy, you can centrally manage the automatic rotation status of keys.
1. On the Cloud Product Key Management page, locate the target key. In the Operation column, click More > Set rotation policy.
2. In the Set Rotation Policy window that pops up, select the key rotation status:
Enable: enable automatic key rotation. After it is enabled, the selected keys are automatically rotated once a year.
Disable: disable automatic key rotation. After it is disabled, the key material of this key is no longer automatically updated.
3. Click OK to complete the settings.
Note:
After a cloud product key is created, its automatic rotation is enabled by default. You can disable or re-enable automatic rotation at any time through the steps described above based on your business or compliance requirements.
After automatic rotation is disabled, the rotated old-version key material is still retained, which does not affect the decryption of existing ciphertexts. New encryption operations use the current latest version of key material.

Rotating Cloud Product Keys Immediately

When a security incident, compliance requirement, or key leakage risk occurs, you can manually trigger an immediate key rotation before the automatic rotation cycle arrives.
1. On the Cloud Product Key Management page, locate the target key. In the Operation column, click More > Rotate Immediately.
2. In the confirmation window that pops up, click OK to trigger immediate rotation.
3. After a key is successfully rotated, the last rotation time in the key list is updated to the current operation time. New encryption operations use the new version of key material, while ciphertexts encrypted before the rotation can still be decrypted normally.
Attention:
Each cloud product key can be rotated immediately only once within 24 hours. Operate with caution to avoid frequent rotations affecting business stability.

Bantuan dan Dukungan

Apakah halaman ini membantu?

masukan