Rolling Encryption Keys
When you roll an EZ key, you are essentially creating a new version of the key
(ezKeyVersionName
). Rolling EZ keys regularly helps enterprises minimize the
risk of key exposure. If a malicious attacker were to obtain the EZ key and decrypt encrypted
data encryption keys (EDEKs) into DEKs, they could gain the ability to decrypt HDFS files.
Rolling an EZ key ensures that all DEKs for newly-created files will be encrypted with the new
version of the EZ key. The older EZ key version that the attacker obtained cannot decrypt these
EDEKs.