Shield External Key Management Considerations
Your Salesforce implementation depends on your external keys to encrypt and decrypt your data. If the key status changes, your users can permanently lose access to encrypted data. Take these considerations into account when managing your external keys.
Required Editions
| Available in both Lightning Experience and Salesforce Classic (not available in all orgs). |
| Available in: Enterprise, Performance, Unlimited, and Developer Editions. Requires purchasing Salesforce Shield or Shield Platform Encryption, and the External Key Management Service. Data 360 customers must also have the Platform Encryption for Consumption license. |
| User Permissions Needed | |
|---|---|
| To generate, destroy, export, import, upload, and configure tenant secrets and customer-supplied key material: | Manage Encryption Keys |
- Make sure that your encryption policy includes key-rotation and key-backup strategies as safeguards against unplanned key loss. Deactivate operations evict encrypted key material from the cache. If an external key or its associated Salesforce data encryption key (DEK) is disabled or deactivated, you can’t access the data encrypted with those keys.
- You can use external keys created in production to decrypt data in a sandbox, but you can’t activate or deactivate those production keys in a sandbox. Create a root key for the sandbox and rotate sandbox DEKs immediately after a refresh. Rotation makes sure that production and sandbox orgs use different DEKs and that you have full control over each of them.
- If a key isn’t available on the external key management service (KMS) and the key is flushed from the cache, Shield Platform Encryption can’t perform encrypt and decrypt operations. Users who try to access encrypted data see three question marks (???) instead of the ciphertext. Any attempts to write data to encrypted fields fail. Users see an error message that says the key is unavailable.
- When the external key isn’t available, we change the status of the key to Unavailable. This means that we stop trying to call the external KMS to get the key. You can check the connection to attempt to reconnect to the key and update its status.
- Platform Encryption for Data 360 manages only External Key Management (EKM) root keys, not DEKs.
- You can’t use EKM to encrypt Backup & Recover Next data.
- With standard Shield Platform Encryption, you can use different keys to encrypt different categories of data like fields, search indexes, and files and attachments. You can only use one key for all of your Data 360 data: either an EKM root key or a Salesforce root key (also known as a customer-managed key).
- When you migrate from a customer managed key to EKM, it affects only new data in Data 360 data sources. Migrating from an EKM key back to a customer-managed key triggers a re-encryption of all data in Data 360 data sources.
- When you use EKM, you can still rotate the other types of keys in Shield Platform Encryption, such as customer-managed keys that you have uploaded or Salesforce-generated keys.
Did this article solve your issue?
Let us know so we can improve!
