On rekey, all existing KMIP objects and any new KMIP objects are encrypted using a new Key Encryption Key (KEK). The HSM must be available before you can rekey. KMIP clients continue to be able to access KMIP objects when the rekey is in progress.

Procedure 

  1. Log in to the Cryptographic Security Platform Vault for KMIP webGUI.
  2. Click Objects.
  3. On the Objects page, select Actions > Rekey All Objects.
  4. At the prompt, click Rekey to re-encrypt KMIP objects using a new KEK.

When the encryption of all KMIP objects completed, an audit log is generated.