Fortinet white logo
Fortinet white logo

FortiDLP Administration Guide

Deleting encryption keys

Deleting encryption keys

If you no longer need an encryption key, you can delete it from the FortiDLP Console and/or FortiDLP Decryption Tool Extension.

Caution

Note the following behavior:

  • When you delete an encryption key from the FortiDLP Console, its public key can no longer be used by the FortiDLP Agent to encrypt new shadow copies and its relative private key can no longer be used by operators to decrypt new shadow copies. However, the private key can be used to decrypt existing shadow copies. For this reason, you should keep your private key protected if you need to continue using it or delete it if you do not.
  • When you delete an encryption key from the FortiDLP Decryption Tool Extension, its public key can continue to be used by the FortiDLP Agent to encrypt new shadow copies, but its relative private key can no longer be used to decrypt new or existing shadow copies. For this reason, you should use caution when deleting keys from the extension, as you will lose the ability to decrypt any shadow copy encrypted with the relative public key.
How to delete an encryption key from the FortiDLP Console
  1. In the FortiDLP Console, on the left-hand sidebar, click .
  2. Under Integrations, select the File shadowing tab.
  3. In the Encryption keys table, on the row of the relevant key, click> Delete key.
  4. In the dialog box, click Delete key.
How to delete an encryption key from the FortiDLP Decryption Tool Extension
  1. On your browser's menu bar, click the icon and launch the FortiDLP Decryption Tool Extension.
  2. In the Passphrase field, type your passphrase and then click Unlock.
  3. On the top-right corner of the extension, click > Manage keys.
  4. In the Previous keys section, below the key you want to delete, click Delete.
  5. In the dialog box, click Delete.

Deleting encryption keys

Deleting encryption keys

If you no longer need an encryption key, you can delete it from the FortiDLP Console and/or FortiDLP Decryption Tool Extension.

Caution

Note the following behavior:

  • When you delete an encryption key from the FortiDLP Console, its public key can no longer be used by the FortiDLP Agent to encrypt new shadow copies and its relative private key can no longer be used by operators to decrypt new shadow copies. However, the private key can be used to decrypt existing shadow copies. For this reason, you should keep your private key protected if you need to continue using it or delete it if you do not.
  • When you delete an encryption key from the FortiDLP Decryption Tool Extension, its public key can continue to be used by the FortiDLP Agent to encrypt new shadow copies, but its relative private key can no longer be used to decrypt new or existing shadow copies. For this reason, you should use caution when deleting keys from the extension, as you will lose the ability to decrypt any shadow copy encrypted with the relative public key.
How to delete an encryption key from the FortiDLP Console
  1. In the FortiDLP Console, on the left-hand sidebar, click .
  2. Under Integrations, select the File shadowing tab.
  3. In the Encryption keys table, on the row of the relevant key, click> Delete key.
  4. In the dialog box, click Delete key.
How to delete an encryption key from the FortiDLP Decryption Tool Extension
  1. On your browser's menu bar, click the icon and launch the FortiDLP Decryption Tool Extension.
  2. In the Passphrase field, type your passphrase and then click Unlock.
  3. On the top-right corner of the extension, click > Manage keys.
  4. In the Previous keys section, below the key you want to delete, click Delete.
  5. In the dialog box, click Delete.