You can delete KeyIDs with the CLI or the webGUI.

Warning: If you confirm and remove the key, you can no longer decrypt any files that were encrypted using the key. You should not remove a KeyID unless you are absolutely sure that it will not be needed to decrypt a file in the future. If you want to temporarily revoke access to the KeyID, see Managing KeyID Access.

Deleting KeyIDs with the CLI

  1. For Linux, log into the VM as root. For Windows, log in as a System Administrator and open a Command Prompt or start Windows PowerShell.
  2. If you want to see the available list of KeyIDs available in this Cloud VM Set, enter the command hcl keyid -l. For example:

    # hcl keyid -l
    Keyid        Algorithm    Description
    -----        ---------    -----------
    hq_key       AES-XTS-512  Secure exchange of HQ data
  3. Enter the command hcl keyid -r keyid-name, where keyid-name is the name of the KeyID you want to delete.
  4. Confirm the removal at the prompt. For example:

    # hcl keyid -r hq_key
    WARNING: Removal of keyid will result in permanent failure to decrypt anything using that keyid.
    Do you want to proceed? (y/n) y

Deleting KeyIDs with the webGUI

  1. Log into the Cryptographic Security Platform Vault for VM Encryption using an account with Cloud Admin privileges.
  2. In the top menu bar, click Workloads.
  3. In the VM Sets tab, select the Cloud VM Set to which the KeyID belongs.
  4. In the Details area below the list of Cloud VM Sets, click the KeyIDs tab.
  5. Select the KeyID you want to delete from the list.
  6. Select Actions > Delete KeyID.
  7. Click Proceed at the prompt.