Encryption key
Adobe Commerce and Magento Open Source use an encryption key to protect passwords and other sensitive data. An industry-standard ChaCha20-Poly1305 algorithm is used with a 256-bit key to encrypt all data that requires encryption. This includes credit card data and integration (payment and shipping module) passwords. In addition, a strong Secure Hash Algorithm (SHA-256) is used to hash all data that does not require decryption.
During the initial installation, you are prompted to either let Commerce generate an encryption key, or enter one of your own. The encryption key tool allows you to change the key as needed. The encryption key should be changed regularly to improve security, and at any time the original key might be compromised.
For technical information, see Advanced on-premises installation in the Installation Guide.
[your store]/app/etc/env.php
To change an encryption key:
The following instructions require access to a terminal.
-
Enable maintenance mode.
code language-bash bin/magento maintenance:enable
-
Disable cron jobs.
Cloud infrastructure projects:
code language-bash ./vendor/bin/ece-tools cron:disable
On-premises projects
code language-bash crontab -e
-
On the Admin sidebar, go to System > Other Settings > Manage Encryption Key.
{width="700" modal="regular"}
-
Do one of the following:
- To generate a new key, set Auto-generate Key to
Yes
. - To use a different key, set Auto-generate Key to
No
. Then in the New Key field, enter or paste the key that you want to use.
- To generate a new key, set Auto-generate Key to
-
Click Change Encryption Key.
note note NOTE Keep a record of the new key in a secure location. It is required to decrypt the data, if any problems occur with your files. -
Flush the cache.
Cloud infrastructure projects:
code language-bash magento-cloud cc
On-premises projects:
code language-bash bin/magento cache:flush
-
Enable cron jobs.
Cloud infrastructure projects:
code language-bash ./vendor/bin/ece-tools cron:enable
On-premises projects:
code language-bash crontab -e
-
Disable maintenance mode.
code language-bash bin/magento maintenance:disable