Files
doc-exports/docs/kms/umn/dew_01_0031.html
qinweiwei 3e4721c813 KMS UMN 20251111 version
Reviewed-by: Rogal, Marcel <mrogal@noreply.gitea.eco.tsi-dev.otc-service.com>
Co-authored-by: qinweiwei <qinweiwei@huawei.com>
Co-committed-by: qinweiwei <qinweiwei@huawei.com>
2026-01-19 09:05:54 +00:00

4.1 KiB

Deleting a Key

Before deleting the key, confirm that it is not in use and will not be used.

Prerequisites

The key to be deleted is in Enabled, Disabled, or Pending import status.

Constraints

  • A key will not be deleted until its scheduled deletion period expires. You can set the period to a value within the range 7 to 1096 days.

    Before the specified deletion date, you can cancel the deletion if you want to use the CMK. Once the scheduled deletion has taken effect, the CMK will be deleted permanently and you will not be able to decrypt data encrypted by the CMK. Exercise caution when performing this operation.

  • Default keys created by KMS cannot be scheduled for deletion.

Procedure

To schedule the deletion of multiple CMKs at a time, select them and click Delete in the upper left corner of the list. The following describes how to delete a single key.

  1. Log in to the management console.
  2. Click in the upper left corner of the management console and select a region or project.
  3. Click on the left and choose Security > Key Management Service.
  4. Locate the target key and click Delete in the Operation column.
  5. On the key deletion dialog box, enter the deletion delay time.

    Figure 1 Setting scheduled deletion

    • A key will not be deleted until its scheduled deletion period expires. You can set the period to a value within the range 7 to 1096 days. Before the specified deletion date, you can cancel the deletion if you want to use the CMK.

  6. Enter DELETE in the confirmation dialog box and click OK.