Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Configure key lifecycle states

After you have created a cryptographic specification, you can configure the lifecycle actions for the keys in your instance.

Before you begin

Role required: sn_kmf.admin

Procedure

  1. Navigate to Key Management > Cryptographic Modules > All.

  2. Select the cryptographic module to configure the lifecycle of a key.

  3. Select a key alias on the Crypto Specifications tab.

Image omitted: key-lifecycle-configuration.jpg
Shows how to select a key from the lifecycle definition.
  1. Select Next.

    The Field Lifecycle Template loads. Default Key Lifecycle values are created based on the selected algorithms for the defined cryptographic specification.

  2. Select a Key Lifecycle from the Applies to column on the Lifecycle Definition step for the crypto specification.

FieldDescription
Applies toSelected key that the lifecycle applies to.
For fieldSelect the type of control for the key that the lifecycle applies to.
Image omitted: field-lifecycle-for-field.jpg
Shows the values in the "For field."
TypeSelect if the valuation for the key lifecycle is a relative value or an absolute value:- Relative: Enter a value that depends on other data entries in the system, such as key generation, activation, and deactivation. - Absolute: Enter an exact value, such as a date.
Lifecycle defaultRead only. Displays a value if set.
OrderEnter the sequence in which to process the key lifecycle state for the crypto specification.
Relative duration typeDuration of the lifecycle: Years, Months, or Days.
Relative durationNumber of years, months, or days the key is valid.
Relative operationBeforeor After.
Relative toField the duration is relative to. Displays if a relative duration or operation is selected.
Image omitted: relative-to-kl-state.jpg
Shows the values of the "Relative to" list.

Parent Topic:Create a cryptographic module