Home icon

AWS CloudHSM architectural considerations for crypto user credential rotation

Security Blog



This article provides guidance on rotating crypto user credentials on AWS CloudHSM clusters, which is an AWS Well-Architected best practice for reducing risks associated with long-term credentials and meeting compliance requirements.

Specifically, the article covers:

  • Three approaches to rotate crypto user passwords with varying levels of downtime, implementation complexity, and infrastructure costs
  • Step-by-step instructions for implementing each approach
  • A comparison matrix to help choose the best approach based on downtime, complexity, and cost requirements
  • Considerations for choosing an approach based on workload needs and business requirements


Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Feb 6
2024
How to migrate asymmetric keys from CloudHSM to AWS KMS
Jul 28
2026
AWS KMS or AWS CloudHSM: Choose the right key management solution
Mar 6
2024
Build a pseudonymization service on AWS to protect sensitive data: Part 2
Feb 14
2024
Cloud-Native Data Security Posture Management Deployments on AWS with Symmetry Systems

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.