Details
-
New Feature
-
Status: Resolved
-
Major
-
Resolution: Fixed
-
None
-
None
-
Reviewed
Description
Currently when an encryption zone (EZ) key is rotated, it only takes effect on new EDEKs. We should provide a way to re-encrypt EDEKs after the EZ key rotation, for improved security.
Attachments
Attachments
Issue Links
- breaks
-
HDFS-12359 Re-encryption should operate with minimum KMS ACL requirements.
- Resolved
-
HDFS-12383 Re-encryption updater should handle canceled tasks better
- Resolved
-
HDFS-12518 Re-encryption should handle task cancellation and progress better
- Resolved
- depends upon
-
HADOOP-13827 Add reencryptEncryptedKey interface to KMS
- Resolved
-
HADOOP-14705 Add batched interface reencryptEncryptedKeys to KMS
- Resolved
-
HDFS-11210 Enhance key rolling to guarantee new KeyVersion is returned from generateEncryptedKeys after a key is rolled
- Resolved
- is depended upon by
-
HDFS-11203 Rename support during re-encrypt EDEK
- Open
- requires
-
HADOOP-14688 Intern strings in KeyVersion and EncryptedKeyVersion
- Resolved