The Vault encryption key is stored in Vault ' s backend storage.
When an auth method is disabled all users authenticated via that method lose access.
When unsealing Vault, each Shamir unseal key should be entered:
You have a 2GB Base64 binary large object (blob) that needs to be encrypted.
How will the Transit secrets engine manage the encryption lifecycle for a large blob?