Rotate the key while nothing is wrong
How platforms replace the keys everything else trusts (token-signing keys, SSH host keys, CA roots, the DNSSEC root KSK), and what happened to the systems that could not.
Reconstructs trust-anchor rotation from the systems that do it on schedule (the DNS root, Entra ID, Sigstore, OpenSSH, Let's Encrypt) and the incidents where it was absent or late: Storm-0558's seven-year-old signing key, DigiNotar's terminal breach, the DST Root CA X3 expiry that broke security vendors, and the postponed first root KSK rollover. A reader leaves with the five-stage reference shape, four decisions with their flip conditions, and a rotation drill with a number attached, the day before the internet's root key rolls for the second time.
Microsoft stopped rotating MSA signing keys in 2021 because a manual rotation had caused a major outage; the fix for an availability incident left the 2016 key alive to become the 2023 security incident, and even the postmortem's crash-dump explanation was later withdrawn for lack of evidence.
What you get out of it
- Rotation is a capability that atrophies exactly when exercising it is scary: the CSRB found rotation stopped entirely in 2021 after an outage, with no tooling to flag overdue keys.
- The verifier population, not the key, sets the blast radius: DST Root CA X3 expired on a date known for years and still broke Palo Alto, Fortinet, Shopify and Auth0 via OpenSSL 1.0.2 path building.
- Uptake telemetry converts an outage into a schedule decision: RFC 8145 data, finalised months earlier, postponed the 2017 root rollover that would have broken ~5% of reporting validators.
- In-band introduction (old key vouches for new: RFC 5011, TUF chaining, UpdateHostKeys) handles every routine roll but inverts on compromise, so the out-of-band path must stay rehearsed.
- If you operate an anchor for others, your verifiers hold a rotation lever you do not control: browsers removed DigiNotar in 2011 and distrusted Entrust in 2024 for remediation failure, not breach size.
Scope
Why this, now. The second-ever DNSSEC root KSK rollover executes on 2026-10-11, the day after this guide's research date, with over 95% of reporting resolvers already carrying the new key.
What it does not cover. Leaf-certificate renewal, the first hour after a leaked secret, and session-token binding, which are covered by the 2026-08-29, 2026-09-20 and 2026-09-30 digs in this category; also HSM internals and the cryptography of key generation itself.
Other field guides
Making a stolen session useless
A field guide to session and token theft, reconstructed from seven public incidents (Okta, Cloudflare x2, BeyondTrust, 1Password, GitHub, Meta, Storm…
26 sources · 22 organisations · 9 postmortemsLetting humans into production
A field guide to the human-access plane: the three legitimate doors into production (automation, pre-validated tooling, audited break-glass), why non…
27 sources · 23 organisations · 5 postmortemsWhen the secret leaks: the hour after exposure
A field guide to the race that starts when a token goes public: who is allowed to kill a credential automatically, how fast the machinery actually wo…
26 sources · 18 organisations · 7 postmortems