Rotation limits the lifetime and impact of a key. Triggers can include expiry, membership change, device loss, suspected compromise or a planned cryptographic transition.
Professional rotation includes creation, distribution, activation, overlap, revocation and deletion. Without a state model, old devices or cached keys may remain effective unnoticed.
Three verification questions
- 01Which events trigger rotation?
- 02How is an incomplete transition handled?
- 03When do old keys become unusable?
