---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Rekey ciphertext with Key Exchange

# Rekey ciphertext with Key Exchange {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

Resource Exchange supports rekeying of ciphertext on the target instance that was encrypted with keys from the source. Rekey activity is tracked in the key life-cycle.

## Overview {#rekey-keyexchange__section_rsc_123_wpb}

Administrators who use KMF for Field Encryption can use Key Exchange to rekey cryptographic keys between production instances when performing data cloning. An active key must first be available on the target instance for rekey, as rekey requires an active key. An
encryption job is automatically created and run by the system to rotate and rekey the source key and re-encrypt the ciphertext.

Use Key Exchange to do the following:  
* Set an expiration time frame for rekey.If the request has expired, then the request is rejected and the key is deleted.

* Automate rekeying ciphertext that was encrypted with keys from source instances.A new cloned crypto key is used to re-encrypt ciphertext on the target instance.

* The Rekey purpose is set up during the cloning process and is automated as part of the clone.
* Rekey activity is tracked on the Modules Key tab of the cryptographic module. Access the Key life cycle state and Key version for key activity. See [Rotate keys](https://servicenow-prod.fluidtopics.net/kC1A~8KQpyWSFSn27nyliQ "For increased security, you can rotate your cryptographic keys on a pre-determined schedule. Key rotation is when you retire an encryption key and replace that old key by generating a new cryptographic key.") for additional information.
{#rekey-keyexchange__ul_awt_323_wpb}

Configure a Key Exchange and select the Enable Rekeying After Key Imported check box for activation. See [Configure Key Exchange](https://servicenow-prod.fluidtopics.net/Q7Ks5vhQ9zLJUWT~ckuUlg "Key Management Framework (KMF) generates automatic key exchange requests for supported cryptographic modules during the fresh installation or upgrade of the instance. manages the data encryption key locally for the instance.") for details.

![Select the Enable Rekeying After Key Imported check box.]()

