-
Type:
New Feature
-
Resolution: Unresolved
-
Priority:
Minor - P4
-
None
-
Affects Version/s: None
-
None
-
None
-
None
-
None
-
None
-
None
-
None
Summary
Add a command to re-encrypt all the encrypted documents of a mapped collection under a new Data Encryption Key (DEK), for key rotation or a provider change.
Proposal* mongodb:encrypted:reencrypt-data reads every document of a mapped collection, decrypts it, re-encrypts the fields client-side with a new DEK, and rewrites the document.
- No driver batch helper exists, so this is a client-side migration. It must run while the application is offline or with planned downtime.
- Part of the Queryable Encryption follow-ups.
Related
- Epic: [PHPLARA-50|https://jira.mongodb.org/browse/PHPLARA-50]
- [DRIVERS-3647|https://jira.mongodb.org/browse/DRIVERS-3647]
- related to
-
PHPLARA-276 Add mongodb:encrypted:rewrap-deks to re-encrypt data keys under a new master KMS
-
- Closed
-