Sri N
Sri N

Reputation: 11

What happens to the CMK Key1 when rotated/expired/deleted and if we use CMK Alias for that CMK Key1: cross-account or even same account references?

What happens to the assets or objects that are encrypted with a "CMK Key1":

  1. Can the new "CMK Key2" which is also attached to the CMK Key1's Alias "CMK ALIAS-xyz" be used for re-encrypting the already existing data objects of the assets that were encrypted with the "CMK Key1", without any DOWNTIME/Code Changes?

  2. When we rotate the Aliased keys, what happens to the direct references to the CMK in the code?

<PLEASE SHARE YOUR PRACTICAL EXPERIENCE - NOT JUST THEORETICAL DOCUMENTATION>

IMAGE - Pictorial representation of above questions

My Current observations:

SUPPORTING ALIASES/Points that say it is possible:

CONCERNs/Points that say it is not possible:

Sources Referred To:

Upvotes: 1

Views: 225

Answers (0)

Related Questions