---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Rotate keys

# Rotate keys {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

For increased security, you can rotate your cryptographic keys on a pre-determined
schedule. Key rotation is when you retire an encryption key and replace that old key by
generating a new cryptographic key.

## Vorbereitungen

Role required: sn_kmf.cryptographic_manager

## Warum und wann dieser Vorgang ausgeführt wird

Encryption modules, unlike encryption contexts, support a rekey of records for re-encryption with a new key. The following demonstrates how to perform a key rotation operation manually on a cryptographic module.

## Prozedur

1. Navigate to Key ManagementCryptographic ModulesAll.
2. Select the cryptographic module for key rotation.
3. On the Module Keys tab, select the Active key.  
   Abbildung : 1. Select the active key  
4. Select Rotate Key.  
   The key life-cycle state changes to "Deactivated." The Last rotated date, Deactivation date, and Key version fields update.
5. Return to Cryptographic Module Module Keys.  
   There's an extra module key listed in the table. The newly rotated key becomes "Active" and the last key is "Deactivated."

