Document system key rotation

Description

New section should be added to the "Data at Rest Encryption":
System key rotation.

In 5.7 and < 8.0.14 it is possible to rotate encryption key used by PS by calling :

SELECT rotate_system_key("percona_binlog");

This will create a new version of binlog encryption key in keyring. This version will be used to encrypt next binlog file.

Environment

None

Smart Checklist

Activity

patrick.birch January 24, 2023 at 3:58 PM

rotate_system_key has been removed.

George Lorch June 20, 2019 at 5:35 PM

please comment here for on what needs to be included in documentation if/when the change from SELECT to ALTER takes place.

Won't Do

Details

Assignee

Reporter

Needs Review

Yes

Time tracking

1h logged

Components

Priority

Smart Checklist

Created May 10, 2019 at 7:40 AM
Updated March 6, 2024 at 12:09 PM
Resolved January 24, 2023 at 3:58 PM