githubEdit

Managing keys

circle-info

This page was generated from content adapted from the AWS Developer Guidearrow-up-right

Creating keys

Enabling and disabling keys

Rotating keys

Using CloudFormation templates

  • Important If you change the value of the KeyUsage, KeySpec, or MultiRegion property of an existing KMS key, the existing KMS key is scheduled for deletion and a new KMS key is created with the specified value. While scheduled for deletion, the existing KMS key becomes unusable. If you don't cancel the scheduled deletion of the existing KMS key outside of AWS CloudFormation, all data encrypted under the existing KMS key becomes unrecoverable when the KMS key is deleted.

Deleting keys

Key state reference

  • Note You might need to scroll horizontally or vertically to see all of the data in this table.

Last updated