Goal
Introduce a supported way to rotate security material after device compromise, migration, or admin action.
Scope
- Decide what needs rotation: request-signing material only or the shared master key as well
- Document the user impact of rotation
- Implement the minimum viable flow
- Ensure old clients fail clearly after rotation
Done when
- Maintainers have a documented recovery path after compromise
Goal
Introduce a supported way to rotate security material after device compromise, migration, or admin action.
Scope
Done when