Scenarios
Key archiving is an archiving process that only supports decryption but not encryption. Tencent Cloud KMS provides the key archiving capability, enabling more comprehensive key management. This document describes how to enable/disable key archiving via the console.
Operation Steps
1. Log in to the KMS (Compliant) console. In the left sidebar, click Key Management > Root Key. 2. On the Root Key Management page, select the key you want to archive. Choose More > Archive Key / Cancel Archive in the operation column to enable or disable key archiving for the selected key.
Attention:
The key archiving feature currently only supports Customer Master Key not occupied by cloud services; other keys are not supported.
The Key arching feature can only be used when the customer master key is in Enabled, Disabled status; it does not support other statuses.
When the key archiving feature is enabled and the key is in Archived status:
Decryption is supported, and Encryption is not supported for the key.
Schedule Deletion, Unarchive, and Edit Tag operations are supported, but Enable Rotation is not supported for the key.
When CMK is in the status of Archived, the storage and calling operations for your key are subject to billing.