Creating new encryption keys

You have the option to create a set of 10,000 new encryption keys that can be used in random key mode.

Before you begin

This task requires the following:
  • The administrator permission Key Rotation Settings is required. By default, this permission is only assigned to the following roles: Global Administrator and Key Manager.
  • We recommend setting the key rotation to Choose a random key per encryption

About this task

Note: Creating new keys too frequently can impair the performance of the eperi sEcure Platform.

Procedure

  1. Navigate to Keys (Encryption Keys) tab.
  2. Click the + New button.


  3. Choose the encryption key type and algorithm from the following choices:
    Type
    • Random Keys
    • Luna HSM
    • Utimaco HSM
    Algorithm
    • AES-256-CBC
    • AES-256-GCM (new)


  4. Click Submit.
  5. If you are running an eperi sEcure Platform cluster, restart the eperi sEcure Platform node where you created the new keys. This ensures that the other nodes will use the new keys.

Results

A set of 10,000 new encryption keys has been created which will now be used for data encryption and decryption. The old keys are retained in order to decrypt data that was encrypted with them.
Note: The new encryption keys are not displayed in the Keys section of the Keys tab.