Uploaded image for project: 'Core Server'
  1. Core Server
  2. SERVER-54060

Implement a switch over between local master encryption key and KMIP master encryption key

    XMLWordPrintable

Details

    • New Feature
    • Status: Investigating
    • Minor - P4
    • Resolution: Unresolved
    • None
    • None
    • None

    Description

      The existing procedure for the switch over from a local master encryption key to a KMIP master encryption key for the Encryption-at-Rest feature requires a wipe-out of the dbPath in the server, followed by a resync.

      Given the size of replica sets in the field, it makes sense to extend the existing KMIP key rotation feature (SERVER-19845), so the customers can move between KMIP and local encryption keys back and forth, avoiding the initial sync procedure. This will save time and data transfer costs.

      Attachments

        Activity

          People

            salman.baset@mongodb.com Salman Baset
            andrey.brindeyev@mongodb.com Andrey Brindeyev
            Votes:
            8 Vote for this issue
            Watchers:
            16 Start watching this issue

            Dates

              Created:
              Updated: