Implement a switch over between local master encryption key and KMIP master encryption key

XMLWordPrintableJSON

    • Type: New Feature
    • Resolution: Unresolved
    • Priority: Minor - P4
    • None
    • Affects Version/s: None
    • Component/s: None
    • None
    • 3
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      The existing procedure for the switch over from a local master encryption key to a KMIP master encryption key for the Encryption-at-Rest feature requires a wipe-out of the dbPath in the server, followed by a resync.

      Given the size of replica sets in the field, it makes sense to extend the existing KMIP key rotation feature (SERVER-19845), so the customers can move between KMIP and local encryption keys back and forth, avoiding the initial sync procedure. This will save time and data transfer costs.

              Assignee:
              Salman Baset (Inactive)
              Reporter:
              Andrey Brindeyev
              Votes:
              9 Vote for this issue
              Watchers:
              20 Start watching this issue

                Created:
                Updated: