You can delete KeyIDs with the CLI or the webGUI.
Warning: If you confirm and remove the key, you can no longer decrypt any files that were encrypted using the key. You should not remove a KeyID unless you are absolutely sure that it will not be needed to decrypt a file in the future. If you want to temporarily revoke access to the KeyID, see Managing KeyID Access.
Deleting KeyIDs with the CLI
- For Linux, log into the VM as
root. For Windows, log in as a System Administrator and open a Command Prompt or start Windows PowerShell. If you want to see the available list of KeyIDs available in this Cloud VM Set, enter the command
hcl keyid -l. For example:# hcl keyid -l Keyid Algorithm Description ----- --------- ----------- hq_key AES-XTS-512 Secure exchange of HQ data
- Enter the command
hcl keyid -r keyid-name, wherekeyid-nameis the name of the KeyID you want to delete. Confirm the removal at the prompt. For example:
# hcl keyid -r hq_key WARNING: Removal of keyid will result in permanent failure to decrypt anything using that keyid. Do you want to proceed? (y/n) y
Deleting KeyIDs with the webGUI
- Log into the Cryptographic Security Platform Vault for VM Encryption using an account with Cloud Admin privileges.
- In the top menu bar, click Workloads.
- In the VM Sets tab, select the Cloud VM Set to which the KeyID belongs.
- In the Details area below the list of Cloud VM Sets, click the KeyIDs tab.
- Select the KeyID you want to delete from the list.
- Select Actions > Delete KeyID.
- Click Proceed at the prompt.