Setting the key rotation

In the Key rotation settings section you define, which encryption keys should be used for encryption transactions.

Procedure

  1. Navigate to Keys (Key Rotation) tab.
  2. Click Key Rotation.
    Figure 1: Key rotation settings
    Key rotation settings
  3. In the Encryption Key drop down menu configure the desired key rotation option and then click Apply.
    Option Description
    Choose a random key per encryption With this option, the eperi sEcure Platform will randomly use a key from the list of automatically generated keys for every encryption transaction.
    Generate a new key per encryption For each encryption operation a new encryption key is generated and used.
    Use an existing key Choose an encryption key that you have previously added using the New Key function (As of release 19.15.1.0 this function is omitted). To configure such a key, start typing the key name in the input field, then select it from the drop down menu.

    Example:

    Important: To be noted in a cluster setup: Each time you change the Key rotation settings, you must restart all eperi sEcure Platform instances except the one where you have changed the setting. This causes the internal key cache to be cleared.

Results

You have successfully configured the key rotation to be applied for encryption transactions. You can change the key rotation setting at any time. Every time Key rotation settings have changed, they will logged in catalina.out.

What to do next

As of release 20.4.1.0 you may adjust the size of the cache containing the keys used for decrypting data. Depending on the number of encryption keys already used, the performance of the decryption can be improved by increasing the cache size. The respective settings are available in the Advanced Settings.