Description
KMS automatic rotation creates a new key version to limit how long the same key material is used. Enable it for supported symmetric keys and choose an interval of 7–365 days that meets organizational requirements.
Potential impact
Disabled rotation or an interval longer than policy permits can keep the same key material in use beyond its intended lifetime.
Remediation
Set automatic_rotation = "Enabled" and a suitable rotation_interval for supported keys. Establish a separate replacement process for imported key material or unsupported key types.
Examples
The examples enable automatic rotation. Seven days is illustrative; rotation does not re-encrypt existing ciphertext.
Before
hcl
resource "alicloud_kms_key" "key" {
description = "Hello KMS"
pending_window_in_days = "7"
status = "Enabled"
automatic_rotation = "Disabled"
}
After
hcl
resource "alicloud_kms_key" "key" {
description = "Hello KMS"
pending_window_in_days = "7"
status = "Enabled"
automatic_rotation = "Enabled"
rotation_interval = "7d"
}