Rotate Asset
Key rotation is supported for PGP, PKI, and SSH keys; it doesn't apply to X509 certificates.
Context
Rotating an asset is the process of generating a new version of the same asset with a different crypto value. Encryption key rotation generates a new version of the asset with a new key value. The status of the previous version (for example, version 1) is set to DecryptOnly when you activate the new version (for example, version 2). The old version is no longer valid for encrypting data; however, it can still be used to decrypt data that was previously encrypted with that version.
Choose the Encryption Keys and Certificates tile to rotate an asset based on the asset category. The Encryption Keys and Certificates List page displays a list of all existing keys and certificates, with corresponding configuration values. All new versions of generated keys need to be activated before use. The new key version is automatically associated with custom fields on activation. You can also update the key metadata, such as adding a new note.
|
Asset Type |
Generate |
Auto-Rotate |
Expiration |
Information |
|---|---|---|---|---|
|
Symmetric Key (DEK) |
✅ |
✅ |
6 months - expiration will begin occurring on or after June 1, 2026. |
Manually created keys will be set to Decrypt once the expiration date is reached and the key will have to be manually rotated. |
|
Public Key Infrastructure (PKI) |
✅ |
✅ |
6 months - expiration will begin occurring on or after September 1, 2026. |
Manually created keys will be set to Decrypt once the expiration date is reached and the key will have to be manually rotated. |
|
Pretty Good Privacy (PGP) Key |
✅ |
❌ |
6 months - expiration will begin occurring on or after June 1, 2026. |
PGP keys cannot be auto-rotated. Generated keys will have to be manually rotated. Customer provided keys will be set to Decrypt once the expiration date is reached and the key will have to be manually rotated. There's a standardized 15 day grace period after the expiration date to allow users to update their systems without disruption. During that time, SAP Fieldglass will continue to support SFTP authentication. Once the grace period is over, if the keys haven't been updated, the system will reject them. Assets can be rotated by creating a new version before expiration. When rotation occurs prior to expiry, the new active version automatically associates with all existing endpoints, eliminating manual remapping. If the asset expires before rotation, a new active asset must be created and manually associated with prior endpoints using the association tab. SAP Fieldglass-generated private keys are available for download on the Self-Service Endpoint details page for users with Configuration Manger User access. |
|
Secure Shell (SSH) Key |
✅ |
✅ |
6 months - expiration will begin occurring on or after July 2026. |
Customer provided keys will be set to Decrypt once the expiration date is reached and the key will have to be manually rotated. There's a standardized 15 day grace period after the expiration date to allow users to update their systems without disruption. During that time, SAP Fieldglass will continue to support SFTP authentication. Once the grace period is over, if the keys haven't been updated, the system will reject them. Assets can be rotated by creating a new version before expiration. When rotation occurs prior to expiry, the new active version automatically associates with all existing endpoints, eliminating manual remapping. If the asset expires before rotation, a new active asset must be created and manually associated with prior endpoints using the association tab. Rotated SSH keys are available for download as public keys for use on SFTP servers. Downloads are accessible from the Encryption Keys and Certificates Details page or the associated endpoint details page. |
|
X.509 |
NA |
NA |
NA |
NA |