After you create a KeyID, you can change the description in either the CLI or the webGUI. In addition, the webGUI allows you to change the expiration date and what happens when the KeyID expires.

Changing the KeyID Description with the CLI

  1. For Linux, log into the VM as root. For Windows, log in as a System Administrator and open a Command Prompt or start Windows PowerShell.
  2. If you want to see the available list of KeyIDs available in this Cloud VM Set, enter the command hcl keyid -l. For example:

    # hcl keyid -l
    Keyid        Algorithm    Description
    -----        ---------    -----------
    hq_key       AES-XTS-512  Secure exchange of HQ data
  3. Enter the command hcl keyid –u [-d "description"], where description is the new description for the KeyID. For example:

    # hcl keyid -u hq_key -d "Key for secure transfer of HQ data"
    # hcl keyid -l
    Keyid        Algorithm    Description
    -----        ---------    -----------
    hq_key       AES-XTS-512  Key for secure transfer of HQ data

Changing KeyID Properties in the webGUI

  1. Log into the Cryptographic Security Platform Vault for VM Encryption using an account with Cloud Admin privileges.
  2. In the top menu bar, click Workloads.
  3. In the VM Sets tab, select the Cloud VM Set to which the KeyID belongs.
  4. In the Details area below the list of Cloud VM Sets, click the KeyIDs tab.
  5. Select the KeyID you want to change from the list.
  6. In the Details area below the KeyID list, you can change the following information:

    Field

    Description

    Description

    A description for the KeyID. This description is shown in the webGUI and the CLI.

    Expiration Date

    The date on which this KeyID expires.

    On Expiration

    What happens when the KeyID expires. You can select:

    • No Use—The key is deactivated but retained. It can then be reactivated by setting a future date in the Expiration Date field. This is the default.
    • Shred—The key is destroyed and cannot be retrieved. You should only use this option if you are absolutely certain that you will never need to decrypt files with the selected KeyID again.