DEV Community

yutianle
yutianle

Posted on

Key rotation as a scheduled operation

Key rotation as a scheduled operation

Rotation appears in every policy document and fails in most implementations for the same reason: the key exists in more places than the team remembers. A rotation that only updates the application and leaves a partner integration on the old key looks successful in the ticket and produces an outage a week later.

Decide what is being rotated

Symmetric data keys, signing keys, TLS certificates and API tokens have different rotation mechanics. A signing key needs an overlap window during which both the old and new public keys are published, so tokens signed before the change still verify. A symmetric key used for encryption needs a key version stored with each ciphertext, or the old key must be kept available until every record is re-encrypted. NIST SP 800-57 Part 1 Revision 5 frames this as a cryptoperiod with defined originator and recipient usage periods.

Two rotation styles

The classic style replaces the key value. The newer style issues a new version and retires the old one after the records and tokens that reference it are gone. The second style costs storage and gives a rollback path; the first is simpler and requires a maintenance window.

Making it repeatable

  1. Inventory every consumer of the key from configuration management, not from memory.
  2. Stage the new key in all consumers before the switch, and verify that both keys are accepted.
  3. Switch the producer, watch the error rate on the consumers that still use the old key.
  4. Remove the old key after the overlap window has passed, and record the date.
  5. Automate the reminder, not the switch, until the inventory has been correct twice in a row.

What usually goes wrong

Manual rotation drifts because it depends on one person remembering. Emergency rotation is slower than planned rotation, which is the opposite of what an incident needs. Keys shared between environments mean a test rotation can break production validation. A rotation runbook that has never been executed end to end is a document, not a control.

References

  • NIST SP 800-57 Part 1 Revision 5, Recommendation for Key Management
  • NIST SP 800-63B, Digital Identity Guidelines (authenticator lifecycle)
  • OWASP Key Management Cheat Sheet

Top comments (0)