ExportXMLWordPrintableJSON

    • Type: New Feature
    • Resolution: Unresolved
    • Priority: Minor - P4
    • None
    • Affects Version/s: None
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Summary

      Add a command to re-encrypt all the encrypted documents of a mapped collection under a new Data Encryption Key (DEK), for key rotation or a provider change.

      Proposal* mongodb:encrypted:reencrypt-data reads every document of a mapped collection, decrypts it, re-encrypts the fields client-side with a new DEK, and rewrites the document.

      • No driver batch helper exists, so this is a client-side migration. It must run while the application is offline or with planned downtime.
      • Part of the Queryable Encryption follow-ups.

      Related

              Assignee:
              Unassigned
              Reporter:
              Jérôme Tamarelle
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated: