-
Type:
New Feature
-
Resolution: Fixed
-
Priority:
Major - P3
-
Affects Version/s: None
-
None
Summary
Add a command to re-encrypt the Data Encryption Keys (DEKs) under a new master key from a different KMS provider, so applications can rotate their master key.
Proposal mongodb:encrypted:rewrap-deks iterates the key vault with ClientEncryption::rewrapManyDataKey(), re-encrypting each DEK under the new master key.
- Used to change the master encryption key (local or a cloud KMS provider).
- Key rotation was previously out of scope in the Queryable Encryption work; this is a planned follow-up. Equivalent of PHPORM-376.
- depends on
-
PHPLARA-275 Add Queryable Encryption support to laravel-mongodb configuration
-
- Closed
-
- is related to
-
PHPLARA-277 Add mongodb:encrypted:reencrypt-data to re-encrypt all documents under a new data encryption key
-
- Ready for Work
-