Re-Keying with New BYOK Keys

Note:

Do not delete the current keys that are being used for encryption.

  1. Create a new ADB Key. Refer to Create the ADB Key. This key should have the IsCurrent tag set to true.
  2. Create a new object storage bucket key. Refer to Create the Object Storage Bucket Key. This key should have the IsCurrent tag set to true.
  3. Remove the IsCurrent tag from the ADB key.
    1. Open the Navigation menu, select Identity & Security, and in the Key Management section, select Vault.
    2. On the Vault page, from the Vault list, select the <VAULT_NAME>.
    3. On the Vaults details page, select Master encryption keys.
    4. Locate the currently used ADB key.
    5. Delete the IsCurrent tag.
  4. Remove the IsCurrent tag from the existing object storage bucket key following the process in the step above.
  5. Create a Service Request ticket for re-encryption. Enter details such as: New Oracle Primavera Cloud BYOK Keys created. Requesting re-encryption of Oracle Primavera Cloud ADB and Object Storage Bucket keys.