Security & Identity 10 Oct 2026 34 min read

Rotate the key while nothing is wrong

How platforms replace the keys everything else trusts (token-signing keys, SSH host keys, CA roots, the DNSSEC root KSK), and what happened to the systems that could not.

Reconstructs trust-anchor rotation from the systems that do it on schedule (the DNS root, Entra ID, Sigstore, OpenSSH, Let's Encrypt) and the incidents where it was absent or late: Storm-0558's seven-year-old signing key, DigiNotar's terminal breach, the DST Root CA X3 expiry that broke security vendors, and the postponed first root KSK rollover. A reader leaves with the five-stage reference shape, four decisions with their flip conditions, and a rotation drill with a number attached, the day before the internet's root key rolls for the second time.

The finding that surprised me

Microsoft stopped rotating MSA signing keys in 2021 because a manual rotation had caused a major outage; the fix for an availability incident left the 2016 key alive to become the 2023 security incident, and even the postmortem's crash-dump explanation was later withdrawn for lack of evidence.

What you get out of it

  • Rotation is a capability that atrophies exactly when exercising it is scary: the CSRB found rotation stopped entirely in 2021 after an outage, with no tooling to flag overdue keys.
  • The verifier population, not the key, sets the blast radius: DST Root CA X3 expired on a date known for years and still broke Palo Alto, Fortinet, Shopify and Auth0 via OpenSSL 1.0.2 path building.
  • Uptake telemetry converts an outage into a schedule decision: RFC 8145 data, finalised months earlier, postponed the 2017 root rollover that would have broken ~5% of reporting validators.
  • In-band introduction (old key vouches for new: RFC 5011, TUF chaining, UpdateHostKeys) handles every routine roll but inverts on compromise, so the out-of-band path must stay rehearsed.
  • If you operate an anchor for others, your verifiers hold a rotation lever you do not control: browsers removed DigiNotar in 2011 and distrusted Entrust in 2024 for remediation failure, not breach size.

Scope

Why this, now. The second-ever DNSSEC root KSK rollover executes on 2026-10-11, the day after this guide's research date, with over 95% of reporting resolvers already carrying the new key.

What it does not cover. Leaf-certificate renewal, the first hour after a leaked secret, and session-token binding, which are covered by the 2026-08-29, 2026-09-20 and 2026-09-30 digs in this category; also HSM internals and the cryptography of key generation itself.

Open the field guide → Self-contained: it loads nothing at read time, follows your system theme, and prints cleanly.