Skip to content

Design and implement key rotation flow #6

Description

@toads

Goal

Introduce a supported way to rotate security material after device compromise, migration, or admin action.

Scope

  • Decide what needs rotation: request-signing material only or the shared master key as well
  • Document the user impact of rotation
  • Implement the minimum viable flow
  • Ensure old clients fail clearly after rotation

Done when

  • Maintainers have a documented recovery path after compromise

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions