Updating Encryption Key
You can update the encryption key of a DB system. You can either use serviced-managed or self-managed encryption key. Updating the encryption key restarts the DB system.
Note
When you use a self-managed key, database operations will be affected if the key is disabled, scheduled for deletion, or deleted. You can enable a disabled key or cancel delete a key in pending deletion to restore full operations of the database. If the key has been deleted without any backup, you will not be able to access the database or backups.
When you use a self-managed key, database operations will be affected if the key is disabled, scheduled for deletion, or deleted. You can enable a disabled key or cancel delete a key in pending deletion to restore full operations of the database. If the key has been deleted without any backup, you will not be able to access the database or backups.
Use one of the following method to update the encryption key of a DB system:
- Using the Console
- Using the REST API, run the UpdateDbSystem operation with the
encryptData
attribute.
Using the Console
Use the Console to update the encryption key of the DB system.
This task requires the following
- A running DB system.
- All required policies have been defined. See Mandatory Policies - User-managed encryption key.
Do the following to update the security certificate of the DB system.
Note
Updating the encryption key restarts the DB system.
Updating the encryption key restarts the DB system.