Every source behind this page, graded. One honesty note: this guide was
researched from an environment whose egress allows GitHub raw content and git but refuses
direct fetches elsewhere; GitHub-hosted sources were fetched raw (and one PR's merge state
verified by git), while all other pages were retrieved through web-search retrieval of
their text. The ledger shipped beside this page records which was which, per source.
Postmortem
Cyber Safety Review Board2024-04
Review of the Summer 2023 Microsoft Exchange Online Intrusion
The definitive account: rotation stopped entirely in 2021 after a rotation-linked
outage, no tooling flagged overdue keys, the 2016 key stayed live, and the theft path
was never established.
Carry forwardThe decision to stop rotating is itself an
architectural decision, and it needs an owner, an expiry and an alert.
cisa.gov PDF
Postmortem
Microsoft MSRC2023-09, upd. 2024-03
Results of Major Technical Investigations for Storm-0558 Key Acquisition
The crash-dump hypothesis, published with specifics, then withdrawn in the March 2024
update: no dump containing the key was found. The investigation outlived its own
conclusion.
Carry forwardCustody logging must outlast the investigation
horizon; a key you cannot trace is a key you must assume fully exposed.
msrc.microsoft.com
Postmortem
GitHub2023-03
We updated our RSA SSH host key
Private key briefly exposed in a public repository; replaced days later at an
announced hour, scoped to one algorithm, with new fingerprints published for
verification. The rare public example of a rehearsed emergency anchor swap.
Carry forwardAn emergency rotation you can execute in days
exists only if the mechanics (staging, comms, fingerprint publication) were built in
peacetime.
github.blog
Postmortem
Scott Helme2021-10
Let's Encrypt Root Expiration - Post-Mortem
The independent tally of who broke when DST Root CA X3 expired: Palo Alto, Cisco
Umbrella, Google Cloud Monitoring, Auth0, Shopify, QuickBooks, Fortinet and more,
overwhelmingly via outdated OpenSSL in appliances.
Carry forwardThe organisations that broke sell security
products; verifier inventory is hard even for experts, so assume yours is incomplete.
scotthelme.co.uk
Postmortem
Fox-IT / DigiNotar2011-09
Interim report, DigiNotar certificate authority breach ("Operation Black Tulip")
531 rogue certificates in ten days, all eight CA servers compromised, 300,000 Iranian
IPs hitting the rogue Google certificate. The report that ended a certificate
authority.
Carry forwardA trust anchor's operator who cannot rotate,
detect and disclose will have the rotation done to them, permanently.
sec.gov (filed copy)
Postmortem
ICANN2020-02
Root Key Signing Key ceremony postponed (the jammed safe)
A malfunctioning safe mechanism blocked access to ceremony material days before the
40th KSK ceremony. No DNSSEC interruption, but the signing calendar slipped and the
safe was drilled open on camera.
Carry forwardThe rotation process has physical and human
dependencies with their own failure modes; they surface only when the process runs.
icann.org
Source
jruby/jruby-openssl2021-10
PR #240: alternative chain building, five years unmerged
A "minimalistic" port of modern alternative-chain verification, opened weeks after the
DST Root X3 breakage. Its head commit is absent from master as of 2026-10 while master
stays active (verified by git in this session).
Carry forwardDo not plan a rotation around a fix landing in
your verifiers; the ecosystem's long tail does not merge on your schedule.
github.com/jruby/jruby-openssl/pull/240
Source
Kubernetes2016-03
Issue #22351: rotated keys do not regenerate issued tokens
The thread that documents the friction: change the service-account key pair and
existing tokens are not re-minted; the workaround is deleting token secrets so the
controller recreates them.
Carry forwardRotating the signer is half the job; have an
answer for every credential the old key already minted.
github.com/kubernetes/kubernetes/issues/22351
Source
OpenSSHsince 6.8 (2015)
ssh_config(5): UpdateHostKeys
The protocol extension that "supports graceful key rotation by allowing a server to
send replacement public keys" into clients' known_hosts after authentication, fetched
raw from the portable tree.
Carry forwardIn-band introduction can be retrofitted onto a
25-year-old trust model; the constraint is deployment lag, not protocol design.
github.com/openssh/openssh-portable
Source
Sigstorechecked 2026-10
root-signing: the trust root operated as pull requests
Five named keyholders with dated terms (two already emeritus), signing events as PRs,
and machinery that "proposes resigning when signatures are close to expiry". Rotation
designed in before the system had users.
Carry forwardKeyholder turnover is a scheduled event, not an
emergency; term limits force the rotation muscle to stay warm.
github.com/sigstore/root-signing
ADR
Kubernetes SIG-Authalpha v1.32
KEP-740: external signing of service account tokens
The design record that names the constraint flatly: keys load at process start, so
"rotating keys require a kube-apiserver to restart", and moves signing behind an RPC so
external key managers can rotate without one.
Carry forwardIf rotation requires a restart of the control
plane, rotation will be deferred; decouple key lifecycle from process lifecycle.
KEP-740
ADR
IETF2007-09
RFC 5011: automated updates of DNSSEC trust anchors
The standards answer to in-band anchor rotation: a new key is accepted only after the
old one vouches for it across a hold-down of "30 days or the expiration time of the
original TTL... whichever is greater", seen in at least two validated sets.
Carry forwardIn-band trust introduction needs a deliberate
delay to blunt a compromised-key race; budget that delay into every rollover plan.
rfc-editor.org/rfc/rfc5011
ADR
The Update Frameworkchecked 2026-10
TUF specification: the root role rotates keys by threshold
Roles hold multiple keys with thresholds; compromise below the threshold cannot reach
clients; new root metadata is signed by the previous root key so continuity is provable
offline.
Carry forwardDesign the key hierarchy so that rotation is a
signed state transition, not an out-of-band migration.
theupdateframework.io/specification
Blog
ICANN2017-09
Update on the Root KSK Rollover Project (the postponement)
Brand-new RFC 8145 telemetry showed ~5% of reporting validators carrying only the old
key; ICANN postponed the first-ever root rollover days before the date, on data that
had not existed six months earlier.
Carry forwardIf uptake telemetry can exist, build it before
the rollover; it converts an outage into a schedule decision.
icann.org
Blog
ICANN2018-10
The recent KSK rollover: summary and next steps
"The result was exceptionally good: There were far fewer Internet users negatively
affected by the change... than anyone expected." The operator's own verdict on the
first roll, written three weeks after it.
Carry forwardA rollover delayed on evidence and executed
with telemetry beats a punctual one executed blind.
icann.org
Blog
ICANN2026-07
Preparing for the root zone KSK rollover (2026-10-11)
KSK-2024 (key tag 38696) published since 2025-01-11; from 2026-10-11 the root signs
only with it; more than 95% of reporting resolvers already signal the new key. The
second roll, run as routine.
Carry forwardThe second rotation is the proof the first one
built a capability rather than survived an event.
icann.org
Blog
Cloudflare2026
The keys to the Internet change on October 11. Are you ready?
The operator's-eye view ahead of the second roll: in 2018 Cloudflare "had seen
resolvers lose their learned trust in the new key during software upgrades or moves
between machines", so publishing early is necessary but not sufficient.
Carry forwardAnchor state is mutable local state; it decays
under rebuilds and migrations, so verify it, do not assume it.
blog.cloudflare.com
Blog
APNIC / Kim Davies2020-03
Drilling for the KSK
The inside account of the jammed-safe ceremony: two safes, HSMs in one, activation
smart cards in the other, and the decision process that ended with a drill and a
locksmith under camera.
Carry forwardWrite down the break-glass path for the
rotation process itself, including who may authorise the drill.
blog.apnic.net
Blog
Let's Encrypt / ISRG2020-12
Extending Android device compatibility (the expired-root cross-sign)
IdenTrust issued a three-year cross-sign for ISRG Root X1 from the expiring DST Root
CA X3, workable because "Android intentionally does not enforce the expiration dates of
trust anchors". A verifier quirk, used deliberately, bought years of compatibility.
Carry forwardVerifier-policy diversity cuts both ways: it
breaks clean rotations and enables clever ones. Know your population's quirks.
letsencrypt.org
Blog
OpenSSL2021-09
Old Let's Encrypt root certificate expiration and OpenSSL 1.0.2
The project's own warning, seventeen days early, that 1.0.2 "always prefers the
untrusted chain" and would follow it to the expired root; the fix is removing the dead
root from the trust store, host by host.
Carry forwardA published warning does not reach the
appliances; assume the long tail reads nothing and plan the chain you serve for
them.
openssl-library.org mirror
Blog
Mozilla2011-09
DigiNotar removal follow up
"A complete removal from our trusted root program", justified by the six-week
nondisclosure. The verifier side of the DigiNotar story: trust-store operators executed
the rotation the CA would not.
Carry forwardDisclosure latency, not breach size, is what
converts a CA incident into a CA removal.
blog.mozilla.org
Blog
Google Chrome Security2024-06
Sustaining digital certificate security: Entrust distrust
Chrome distrusted Entrust TLS issuance after "a pattern of compliance failures, unmet
improvement commitments" across six years: the slow-motion version of the verifier-side
rotation lever, with a dated SCT cutoff instead of an emergency removal.
Carry forwardRoot programs now rotate out operators, not
just keys; remediation velocity is part of what keeps an anchor trusted.
security.googleblog.com
Blog
CNCF / Sigstore2021-06
A new kind of trust root (the first ceremony)
Five community keyholders generated keys on hardware tokens during a live-streamed
ceremony and signed the initial TUF root: a trust anchor born with its rotation
protocol already public.
Carry forwardThe cheapest time to design rotation is before
the first verifier exists.
cncf.io
Blog
Let's Encrypt / ISRG2025-12
10 years (the issuance machine under one root)
"Frequently issuing ten million certificates per day" as of late 2025. The scale
number that explains why root and intermediate hygiene at ISRG is an industrial
process, not a ceremony-only affair.
Carry forwardThe more leaves a root carries, the more its
rotation resembles a migration programme with a comms plan.
letsencrypt.org
Blog
Red Hat2018
What you need to know about the first-ever DNSSEC root key rollover
Operator guidance from the resolver-vendor side, including the catch for late joiners:
configure close to the roll and "you no longer have 30 days for the hold timer", so the
new key goes in by hand.
Carry forwardAutomated trust acquisition has a minimum
runway; systems built inside that runway need the manual path documented.
redhat.com
Paper
Müller et al., IMC 20192019-10
Roll, Roll, Roll Your Root (Distinguished Paper)
Independent multi-vantage measurement of the 2018 rollover: "generally did not lead to
problems for end users", but "under the hood, a number of issues occurred", including
telemetry polluted by non-resolver signals.
Carry forwardInstrument the rollover independently of the
operator's own dashboard; the operator's success metric is user harm, yours is
mechanism health.
par.nsf.gov (PDF)
Paper
Osterweil et al.2021 (TNSM 2022)
From the Beginning: key transitions in the first 15 years of DNSSEC
Fifteen years of measured key transitions show "measurable gaps relative to prescribed
key management processes", and the authors argue noncompliant transitions are
inevitable at ecosystem scale.
Carry forwardDesign rotation procedures that degrade safely
when half-followed, because at scale they will be.
arxiv.org/abs/2109.08783
Paper
Samuel, Mathewson, Cappos, Dingledine (CCS 2010)2010
Survivable Key Compromise in Software Update Systems
The TUF paper: start from the assumption that keys will be compromised, then derive
thresholds, role separation and offline roots so that rotation, not secrecy, is the
survival mechanism.
Carry forward"How do we rotate after compromise" is a
design-time question; retrofitting it is what section 4 looks like.
uptane.org (PDF)
Talk
Matt Larson (ICANN), DNS-OARC 282018-03
Update on root KSK rollover (or, We're really doing it this time)
The operator community briefing between postponement and execution: what the RFC 8145
data showed, what could and could not be inferred from it, and the plan to proceed in
October 2018.
Carry forwardPublishing your telemetry readout to the people
it measures is part of the rollover, not PR around it.
indico.dns-oarc.net
Talk
Edward Lewis (ICANN), NLUUG2017-05
2017 DNSSEC KSK rollover
The plan as presented to operators while KSK-2017 sat published but idle: the key
"ready for operations but not yet in use", and the staged schedule that the September
telemetry would later interrupt.
Carry forwardA published-but-unused successor key is a
cheap, reversible first step every anchor operator can take today.
nluug.nl
Vendor
Microsoftliving doc
Signing key rollover in the Microsoft identity platform
The issuer's explicit contract: keys roll periodically and "in an emergency, could be
rolled over immediately"; relying apps must handle it programmatically, cache JWKS for
24 hours, and refetch on an unknown kid.
Carry forwardPublish your rotation contract to consumers as
documentation with numbers, then test consumers against it.
learn.microsoft.com
Vendor
AWSchecked 2026-10
KMS pricing, and KMS versus CloudHSM
$1 per customer-managed key per month plus $0.03 per 10,000 requests; a dedicated
CloudHSM instance at $1.60/hour, about $1,152 a month, doubled for HA. The three-orders
-of-magnitude custody cost spread, from the vendor's own pages.
Carry forwardCustody cost is not the constraint for most
teams; the constraint is which custody tier makes rotation automatic.
aws.amazon.com/kms/pricing
Blog
SecurityWeek / TechTarget (on Microsoft SFI)2023-11 / 2024-09
The structural fix: automated rotation in managed HSM, shipped
At the Secure Future Initiative launch: "Key rotation will also be automated allowing
high-frequency key replacement with no potential for human access." A year later the
progress report lists Entra and MSA signing keys generated, stored and auto-rotated in
Azure Managed HSM as complete.
Carry forwardThe post-incident fix for a seven-year-old key
was not a better calendar reminder; it was removing humans from the rotation loop
entirely.
securityweek.com
Vendor
ICANN / Verisign2024-2026
KSK-2024: generated under vendor pressure, rolled on telemetry
The new root key was generated in April 2024 after the HSM supplier announced its
exit; Verisign's observations note the planned three-year rotation cycle had stretched
to eight via the pandemic and hardware end-of-support.
Carry forwardAnchor rotation schedules slip for boring
reasons; the slippage, not the ceremony, is the risk to manage.
icann.org