Estados de clave de de las claves AWS KMS - AWS Key Management Service

Las traducciones son generadas a través de traducción automática. En caso de conflicto entre la traducción y la version original de inglés, prevalecerá la version en inglés.

Estados de clave de de las claves AWS KMS

Una AWS KMS key siempre tiene un estado de clave. Las operaciones en la clave KMS y su entorno pueden cambiar ese estado de clave, ya sea de forma transitoria, o hasta que otra operación cambie su estado clave.

La tabla de esta sección muestra cómo los estados clave afectan a las llamadas a operaciones de la API de AWS KMS. Como resultado de su estado clave, se espera que una operación en una clave KMS tenga éxito (), falle (X), o tenga éxito solo bajo ciertas condiciones (?). El resultado a menudo difiere en el caso de las claves KMS con material de claves importado.

Esta tabla incluye sólo las operaciones de API que utilizan una clave KMS existente. Otras operaciones, como CreateKey y ListKeys, se omiten.

Estados clave y tipos de claves KMS

El tipo de clave KMS determina los estados clave que puede tener.

  • Todas las claves KMS pueden estar en los estados Enabled, Disabled y PendingDeletion.

  • La mayoría de las claves KMS se crean en el estado Enabled. Las claves con material de claves importado se crean en el estado PendingImport.

  • El estado PendingImport solo se aplica a las claves KMS con material de claves importado.

  • El estado Unavailable se aplica solo a una clave KMS en un almacén de claves personalizado. Una clave de KMS en un almacén de claves de AWS CloudHSM está Unavailable cuando el almacén de claves personalizado se desconecta de forma intencionada de su clúster de AWS CloudHSM. Una clave de KMS en un almacén de claves externo está Unavailable cuando el almacén de claves personalizado se desconecta de forma intencionada de su proxy del almacén de claves externo. Puede ver y administrar las claves KMS no disponibles, pero no puede usarlas en operaciones criptográficas.

    El estado de clave de una clave de KMS de un almacén de claves personalizado no se ve afectado por los cambios realizados a su clave de respaldo. Una clave de KMS de un almacén de claves de AWS CloudHSM no se ve afectada por los cambios realizados en el material de claves asociado en el clúster de AWS CloudHSM. Una clave de KMS de un almacén de claves externo no se ve afectada por los cambios en su clave externa en un administrador de claves externo. Si la clave de respaldo está deshabilitada o eliminada, el estado de la clave de KMS no cambia, pero fallan las operaciones criptográficas que utilizan la clave de KMS.

  • Los estados clave Creating, Updating y PendingReplicaDeletion solo se aplican a claves de varias regiones.

    • Una clave de réplica de varias regiones está en el estado de clave Creating transitorio mientras se está creando. Este proceso aún puede estar en curso cuando se complete la operación ReplicateKey. Cuando se completa el proceso de replicación, la clave de réplica se encuentra en el estado Enabled o PendingImport.

    • Las claves de varias regiones están en el estado clave Updating transitorio mientras se actualiza la región principal. Este proceso aún puede estar en curso cuando se completa la operación UpdatePrimaryRegion. Cuando se completa el proceso de actualización, las claves principal y de réplica reanudan el estado de clave Enabled.

    • Cuando se programa la eliminación de una clave principal de varias regiones que tiene claves de réplica, la clave principal se encuentra en el estado PendingReplicaDeletion hasta que se eliminen todas sus claves de réplica. A continuación, el estado de clave cambia a PendingDeletion. Para obtener más información, consulte Deleting multi-Region keys.

Tabla estado de claves

En la siguiente tabla se muestra cómo el estado de clave de una clave KMS afecta las operaciones de AWS KMS.

Las descripciones de las notas numeradas a pie de página ([n]) se encuentran al final de este tema.


Es posible que tenga que desplazarse horizontal o verticalmente para ver todos los datos de esta tabla.

API Habilitado Deshabilitad

Eliminación pendiente

Eliminación pendiente de réplica

Importación pendiente No disponible Creación Actualización
CancelKeyDeletion No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.


Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.

[4], [13]

No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.


CreateAlias Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.


Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion.
CreateGrant Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.

[2] o [3]

No entry symbol with a person icon, indicating restricted access or prohibition.


Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.


Green checkmark icon indicating success or completion.
Decrypt Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.

[2] o [3]

No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.


Green checkmark icon indicating success or completion.
DeleteAlias Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion.
DeleteImportedKeyMaterial Green checkmark icon indicating success or completion.


Green checkmark icon indicating success or completion.


Green checkmark icon indicating success or completion.


Green checkmark icon indicating success or completion.

(sin efecto)

N/A No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.


DescribeKey Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion.
DisableKey Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.


Green checkmark icon indicating success or completion.


No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.


DisableKeyRotation Question mark icon in a purple circle, representing help or information.


No entry symbol with a person icon, indicating restricted access or prohibition.

[1] o [7]

No entry symbol with a person icon, indicating restricted access or prohibition.

[3] o [7]

No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.


Question mark icon in a purple circle, representing help or information.


EnableKey Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.


Green checkmark icon indicating success or completion.


No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.


EnableKeyRotation Question mark icon in a purple circle, representing help or information.


No entry symbol with a person icon, indicating restricted access or prohibition.

[1] o [7]

No entry symbol with a person icon, indicating restricted access or prohibition.

[3] o [7]

No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.


Question mark icon in a purple circle, representing help or information.


Encrypt Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.

[2] o [3]

No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.


Green checkmark icon indicating success or completion.
GenerateDataKey Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.

[2] o [3]

No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.


Green checkmark icon indicating success or completion.
GenerateDataKeyPair Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.

[2] o [3]

No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.


Green checkmark icon indicating success or completion.
GenerateDataKeyPairWithoutPlaintext Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.

[2] o [3]

No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.


Green checkmark icon indicating success or completion.
GenerateDataKeyWithoutPlaintext Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.

[2] o [3]

No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.


Green checkmark icon indicating success or completion.
GenerateMac Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.

[2] o [3]

N/A N/A No entry symbol with a person icon, indicating restricted access or prohibition.


Green checkmark icon indicating success or completion.
GetKeyPolicy Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion.
GetKeyRotationStatus Question mark icon in a purple circle, representing help or information.


Question mark icon in a purple circle, representing help or information.


Question mark icon in a purple circle, representing help or information.


No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.


Question mark icon in a purple circle, representing help or information.


Question mark icon in a purple circle, representing help or information.


GetParametersForImport Question mark icon in a purple circle, representing help or information.


Question mark icon in a purple circle, representing help or information.


No entry symbol with a person icon, indicating restricted access or prohibition.

[8] o [9]

Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.


GetPublicKey Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.

[2] o [3]

N/A N/A No entry symbol with a person icon, indicating restricted access or prohibition.


Green checkmark icon indicating success or completion.
ImportKeyMaterial Question mark icon in a purple circle, representing help or information.


Question mark icon in a purple circle, representing help or information.


No entry symbol with a person icon, indicating restricted access or prohibition.

[8] o [9]

Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.


Green checkmark icon indicating success or completion.
ListAliases Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion.
ListGrants Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion.
ListKeyPolicies Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion.
ListKeyRotations Question mark icon in a purple circle, representing help or information.


Question mark icon in a purple circle, representing help or information.


Question mark icon in a purple circle, representing help or information.


No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.


Question mark icon in a purple circle, representing help or information.


Question mark icon in a purple circle, representing help or information.


ListResourceTags Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion.
PutKeyPolicy Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion.
ReEncrypt Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.

[2] o [3]

No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.


Green checkmark icon indicating success or completion.
ReplicateKey Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.

[2] o [3]

No entry symbol with a person icon, indicating restricted access or prohibition.


N/A No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.


RetireGrant Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion.
RevokeGrant Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion.
RotateKeyOnDemand Question mark icon in a purple circle, representing help or information.


No entry symbol with a person icon, indicating restricted access or prohibition.

[1] o [7]

No entry symbol with a person icon, indicating restricted access or prohibition.

[3] o [7]

No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.


Question mark icon in a purple circle, representing help or information.


ScheduleKeyDeletion Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.


Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.


Sign Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.

[2] o [3]

N/A N/A No entry symbol with a person icon, indicating restricted access or prohibition.


Green checkmark icon indicating success or completion.
TagResource Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.


Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion.
UntagResource Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.


Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion.
UpdateAlias Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Question mark icon in a purple circle, representing help or information.


Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion.
UpdateKeyDescription Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.


Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion. Green checkmark icon indicating success or completion.
UpdatePrimaryRegion Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.

[2] o [3]

No entry symbol with a person icon, indicating restricted access or prohibition.


N/A No entry symbol with a person icon, indicating restricted access or prohibition.


Green checkmark icon indicating success or completion.
Verificar Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.

[2] o [3]

N/A N/A No entry symbol with a person icon, indicating restricted access or prohibition.


Green checkmark icon indicating success or completion.
VerifyMac Green checkmark icon indicating success or completion. No entry symbol with a person icon, indicating restricted access or prohibition.


No entry symbol with a person icon, indicating restricted access or prohibition.

[2] o [3]

N/A N/A No entry symbol with a person icon, indicating restricted access or prohibition.


Green checkmark icon indicating success or completion.

Detalles de la tabla

  • [1] DisabledException: <key ARN> is disabled.

  • [2] DisabledException: <key ARN> is pending deletion (or pending replica deletion).

  • [3] KMSInvalidStateException: <key ARN> is pending deletion (or pending replica deletion).

  • [4] KMSInvalidStateException: <key ARN> is not pending deletion (or pending replica deletion).

  • [5] KMSInvalidStateException: <key ARN> is pending import.

  • [6] UnsupportedOperationException: <key ARN> origin is EXTERNAL which is not valid for this operation.

  • [7] Si la clave KMS tiene material de claves importado o está en un almacén de claves personalizado: UnsupportedOperationException.

  • [8] Si la clave KMS tiene material de claves importado: KMSInvalidStateException

  • [9] Si la clave KMS no puede tener o no tiene material de claves importado: UnsupportedOperationException.

  • [10] Si la clave KMS de origen está pendiente de eliminación, el comando se ejecuta satisfactoriamente. Si la clave KMS de destino está pendiente de eliminación, el comando genera el error: KMSInvalidStateException : <key ARN> is pending deletion.

  • [11] KMSInvalidStateException: <key ARN> is unavailable. No puede realizar esta operación en una clave KMS no disponible.

  • [12] La operación se ha realizado correctamente pero el estado de clave de la clave KMS no cambiará hasta que esté disponible.

  • [13] Mientras una clave KMS en el almacén de claves personalizado esté pendiente de eliminación, su estado de clave seguirá siendo PendingDeletion incluso si la clave KMS no está disponible. Esto permite cancelar la eliminación de la clave KMS en cualquier momento durante el período de espera.

  • [14] KMSInvalidStateException: <key ARN> is creating. AWS KMS lanza esta excepción mientras está replicando una clave de varias regiones (ReplicateKey).

  • [15] KMSInvalidStateException: <key ARN> is updating. AWS KMS lanza esta excepción mientras actualiza la región principal de una clave de varias regiones (UpdatePrimaryRegion).