Starting with release 10.5.3, you can use on-demand key rotation with BYOK, with native AWS support for key versions. The following caveats apply to on-demand key rotation: 

  • Only AES keys can be rotated using on-demand rotation. Non-symmetric encryption keys and HMAC keys are not supported.

  • You can rotate a key using on-demand rotation only 10 times, for a total of 11 versions.

  • You can delete key versions created using on-demand rotation only from the cloud or by uploading them to the cloud. You cannot disable them or schedule them for deletion.

  • When the master key is scheduled for deletion, all versions of the key created using on-demand rotation are also scheduled for deletion.

If AWS created the initial key versions, CSP Vault cannot rotate this key using on-demand rotation after it is imported. This is because each on-demand rotation must have the same key material source. Therefore, you must create any subsequent key versions in AWS and then sync them to CSP using the import functionality. For example, if the key source is AWS KMS, you can import the key but cannot use on-demand rotation in the CSP Vault. You will need to rotate the key in AWS and then re-import the key.

To enable on-demand key rotation for AWS AES keys with BYOK

  1. Create a CloudKey for AWS BYOK.

  2. On the Purpose tab, select AES-256 for the algorithm.

  3. Check the Use on-demand key rotation for new versions checkbox.

  4. Continue creating the key as normal.

  5. After the key is created, click the Details tab and scroll down to the Rotation Schedule section.

  6. Check that the new Use on-demand rotations field reads True.

    • If this value is set to False, you can change it to True if the key only has a single version.

    • If it is set to True, you cannot modify its value.