Certificate rotation and restore tabletop
Work through certificate renewal and restoration on paper. Identify owners, dependencies and recovery steps for expiry and broken trust relationships.
Sources and scopeSource record 25 August 2026
Technical source record: 25 August 2026. Check the linked documentation for current product requirements.
Offline research and planning only; product or deployment acceptance belongs to separately governed environment validation.
On this page
Overview#
Lab class: Tabletop
Scenario#
A management service issuing CA will expire in 30 days. Cameras, controllers, gateways, brokers and operator clients trust it through different deployment mechanisms. A recent backup contains the old trust state, and several field devices can be updated only through a gateway.
Discussion sequence#
- Inventory every certificate, trust anchor, service name, client and owner.
- Identify firmware/client limitations and whether dual trust/overlap is supported.
- Establish trustworthy time and alerting.
- Define issuance, key generation/storage and approval for the replacement chain.
- Sequence trust anchor distribution before leaf replacement without creating an unintended broader trust set.
- Define validation evidence, hold points and rollback at each cohort.
- Determine how restored backups avoid reinstating expired or compromised trust.
- Plan emergency revocation/distrust and temporarily disconnected assets.
- Define safe service behaviour when validation fails; reject plaintext/accept all fallback.
Outputs#
Produce a certificate inventory, dependency graph, cohort sequence, overlap window, monitoring plan, rollback plan, backup reconciliation rule, ownership map, and separately governed environment validation cases.
Review checklist#
- Certificate, service name, trust anchor, client, owner, and expiry inventory completed
- Dual trust, firmware/client limitations, time dependency, and cohort constraints mapped
- Key generation/storage, issuance approval, trust distribution, and leaf replacement sequenced
- Hold points, monitoring evidence, rollback, and emergency distrust/revocation decisions assigned
- Backup restoration can't silently reinstate expired or compromised trust
- Validation failure rejects plaintext, accept all, and unapproved bypass behaviour
- Physical or operational certificate acceptance cases routed outside the tabletop
Sources#
- RFC 5280, accessed 25 August 2026.