notary icon indicating copy to clipboard operation
notary copied to clipboard

What happens when certificate expire?

Open rroques opened this issue 4 years ago • 1 comments

Hi all,

Looking at the documentation for key management and the expiry dates, can you please detail what the standard operational procedure would look like to renew certificates before they expire?

My understanding is that, before the delegation/targets keys expire 3 years after creation, they must be rotated. Rotating the keys will invalidate the old keys, making the previously signed data untrusted, and will involve having to re-sign all data with the new keys. Is that correct?

Many thanks.

rroques avatar Jul 27 '20 18:07 rroques

That is correct. Every content signed with the expired/old rotated keys must be resigned.

IAL32 avatar Nov 17 '21 13:11 IAL32