Unable delete Route53 hostedzones

0

I can't delete hostedzones, it prompts: HostedZoneNotEmpty 400: The specified hosted zone contains DNSSEC Key Signing Keys and so cannot be deleted., but I already deleted it in the KMS console.

Kincaid
已提問 2 年前檢視次數 523 次
1 個回答
0

I haven't used DNSSEC myself yet but I'm assuming the usual restrictions on KMS key deletion apply. You can't delete KMS keys immediately, only schedule them for deletion with a min 7 days, default 30 days waiting period.

This is to protect you - deleting a customer master key is destructive and potentially dangerous. It deletes the key material and all metadata associated with the CMK, and is irreversible. After a CMK is deleted you can no longer decrypt the data that was encrypted under that CMK, which means that data becomes unrecoverable.

專家
已回答 2 年前

您尚未登入。 登入 去張貼答案。

一個好的回答可以清楚地回答問題並提供建設性的意見回饋,同時有助於提問者的專業成長。

回答問題指南