kosa8 docs

Commands / kosa8 key rotate

kosa8 key rotate

Rewrap every snapshot key under a new KEK and destroy the old one

Creates a new KEK, rewraps every snapshot's data key under it, and then overwrites and deletes the old KEK. Snapshots here keep opening. Every copy of a key record wrapped under the old KEK — in a pushed snapshot, an exported bundle, a backup — stops opening anywhere: this is the crypto-shred that reaches copies kosa8 cannot delete. Machines that share the old KEK must import the new one to keep exchanging snapshots. Audited.