Master Key Rotation
You can rotate the Master Key using any of the following two methods:
Without Key Caching
Open
CADP_PKCS11.properties
file and ensure thatSymmetric_Key_Cache_Enabled
property is set tono
.Open the wallet.
Rotate the Master Encryption Key.
OR
With Key Caching
Open
CADP_PKCS11.properties
file and ensure thatSymmetric_Key_Cache_Enabled
property is set toyes
.From the CipherTrust Manager UI, make the MEK as exportable.
Restart the database and open the wallet.
Rotate the master encryption key using any of the following commands.
OR
From the CipherTrust Manager UI, make the newly generated key as exportable.