February 2020
Intermediate to advanced
440 pages
13h 51m
English
When we specify the option to automatically rotate this CMK every year, AWS will rotate the CMK every year, but keeps a copy of the old backing key in order to decrypt any data that was encrypted with the old backing key. AWS keeps the older backing keys until we delete them.
With automatic rotation, only the backing key of a CMK is rotated. This means that the CMK ID, ARN, region, policies, permissions, and other properties remain the same. Therefore, we do not need to change applications or aliases that use a CMK.
Read now
Unlock full access