Learn how to securely rotate AWS KMS keys without data loss. Find strategies for rotating KMS keys used for generating data keys and in EBS volumes. Understand the different types of KMS keys and their ownership. Discover the recommended approaches for key material and the options for key storage. Explore the process of re-encrypting data keys and changing the default KMS key for S3 buckets. Find out how to rotate KMS keys in other AWS services and the considerations for customer-generated key material.
Table of contents
Where do KMS keys come from?Ways to rotate a KMS keyWhat to do when a key is compromisedWrapping upReferencesSort: