Credentials stored within three external data entities—NamedCredential, ExternalDataUserAuth, and ExternalDataSource—are now encrypted under a framework that is consistent with other encryption frameworks on the platform. Salesforce encrypts your credentials using org-based keys instead of pod or instance-level keys, giving your third-party data an extra layer of security.
Where: This change applies to Lightning Experience and Salesforce classic in all editions.
How: Your secret keys are auto-created by the new encryption framework. Credentials encrypted using the previous encryption scheme are being migrated to the new framework. All new credentials will use the new framework.