For EDB PostgreSQL, we highly recommend rotating keys only manually because key rotation in EDB will not change the Data Encryption Key (DEK). Only the wrapping key rotates. 

Manually rotating the CloudKey wrapping

See below for manually rotating the CloudKey wrapping

To rotate the CloudKey wrapping

  1. Log in to the Vault web GUI.

  2. In the top menu bar, click CloudKeys.

  3. Select the CloudKeys tab, and then select the appropriate Key Set.

  4. Select the specific CloudKey you want to apply scheduled key rotation to.

  5. Select the Details tab and then click Rotate Now in the Rotation Schedule row.

  6. Click Save.

Manually rotating the key in EDB PostgreSQL

After you have rotated the CloudKey, run the following: 

cd $PGDATA/pg_encryption/
/opt/hcs/bin/htkey decrypt --config-file <config-file-path> --in-file key.bin | /opt/hcs/bin/htkey encrypt --config-file <config-file-path> --key-name <key-name> --out-file key.bin.new
mv key.bin.new key.bin 
Where: 
  • <config-file-path> is the absolute path of the Access Token file. 

  • <key-name> is the CloudKey that you just rotated.

Rewrapping the data encryption key

After you rotate the wrapping key, you will need to rewrap the DEK (Data Encryption Key) located at the following path.

$PGDATA/pg_encryption/key.bin