Rotate Asset

Key rotation is supported for PGP, PKI, and SSH keys; it doesn't apply to X509 certificates.

Context

Rotating an asset is the process of generating a new version of the same asset with a different crypto value. Encryption key rotation generates a new version of the asset with a new key value. The status of the previous version (for example, version 1) is set to DecryptOnly when you activate the new version (for example, version 2). The old version is no longer valid for encrypting data; however, it can still be used to decrypt data that was previously encrypted with that version.

Choose the Encryption Keys and Certificates tile to rotate an asset based on the asset category. The Encryption Keys and Certificates List page displays a list of all existing keys and certificates, with corresponding configuration values. All new versions of generated keys need to be activated before use. The new key version is automatically associated with custom fields on activation. You can also update the key metadata, such as adding a new note.

Asset Type

Generate

Auto-Rotate

Expiration

Information

Symmetric Key (DEK)

6 months - expiration will begin occurring on or after June 1, 2026.

Manually created keys will be set to Decrypt once the expiration date is reached and the key will have to be manually rotated.

Public Key Infrastructure (PKI)

6 months - expiration will begin occurring on or after September 1, 2026.

Manually created keys will be set to Decrypt once the expiration date is reached and the key will have to be manually rotated.

Pretty Good Privacy (PGP) Key

6 months - expiration will begin occurring on or after June 1, 2026.

PGP keys cannot be auto-rotated. Generated keys will have to be manually rotated. Customer provided keys will be set to Decrypt once the expiration date is reached and the key will have to be manually rotated.

There's a standardized 15 day grace period after the expiration date to allow users to update their systems without disruption. During that time, SAP Fieldglass will continue to support SFTP authentication. Once the grace period is over, if the keys haven't been updated, the system will reject them.

Assets can be rotated by creating a new version before expiration. When rotation occurs prior to expiry, the new active version automatically associates with all existing endpoints, eliminating manual remapping. If the asset expires before rotation, a new active asset must be created and manually associated with prior endpoints using the association tab.

SAP Fieldglass-generated private keys are available for download on the Self-Service Endpoint details page for users with Configuration Manger User access.

Secure Shell (SSH) Key

6 months - expiration will begin occurring on or after July 2026.

Customer provided keys will be set to Decrypt once the expiration date is reached and the key will have to be manually rotated.

There's a standardized 15 day grace period after the expiration date to allow users to update their systems without disruption. During that time, SAP Fieldglass will continue to support SFTP authentication. Once the grace period is over, if the keys haven't been updated, the system will reject them.

Assets can be rotated by creating a new version before expiration. When rotation occurs prior to expiry, the new active version automatically associates with all existing endpoints, eliminating manual remapping. If the asset expires before rotation, a new active asset must be created and manually associated with prior endpoints using the association tab.

Rotated SSH keys are available for download as public keys for use on SFTP servers. Downloads are accessible from the Encryption Keys and Certificates Details page or the associated endpoint details page.

X.509

NA

NA

NA

NA

Procedure

  1. To manually rotate an asset, in the Action column, choose View Details in the corresponding row of the asset you want to rotate.

    The selected asset opens on the Asset Configuration page on the Details tab.

  2. On the top-right side of the page, choose Edit.

    The Asset Edit page opens.

  3. In the Public Key field (for PKI or PGP key) or Symmetric Key field, replace the current value with a new valid key value, or choose the Generate option. Optionally choose Auto-Rotate if you want the key to begin automatically rotating once activated.
  4. Choose Save.
  5. Activate the new key. For task instructions, see Create, Generate, and Activate Asset.