Transferring ownership of encryption keys

System security officers and key owners can use alter encryption key or alter... modify owner to transfer encryption keys.

For information about the alter encryption key command, see Reference Manual: Commands.


Encryption key copy owners

When using the alter... modify owner command, the user who has been assigned a key copy cannot be the new owner of the encryption key.

After the owner of a encryption key changes, the assignees of key copies do not change. For example, user bill owns an encryption key named bill.encrkey and creates one key copy of the key, which he assigns to mark. After bill transfers the ownership of bill.encrkey to eric, mark still owns a copy of bill.encrkey.