Operator · CAs & Hierarchy

Generations, Not Renames

Frame 30 of 107

Your issuing CA's key expires in a year. In most shops that kicks off a renaming project: ica-tls-2027, new URLs, every template and client updated by hand. goca refuses the premise.

A generation is a CA's key + certificate at one point in its life. Rollover creates generation N+1 under the same logical CA — templates, bindings and clients keep addressing the logical name and never notice. The name is the stable thing; the key material is what ages.

The console leans into this: Configuration → CAs opens on a table of generations, one row per generation, not per CA — because the questions an estate raises are generation questions. Which key is active? Which expires first? Which is still on a software key? (Custody is software) What has ever rolled? (Gen is greater than 1).

Metaphor: the office of mayor versus the person holding it. Citizens address the office; elections change the occupant.
Where it breaks: an outgoing mayor stops working. An outgoing generation keeps signing its own CRLs until its issued population expires — revocation for old certificates never breaks.

Now I can tell a CA from its generation — and say which one clients address.