Operator · CAs & Hierarchy

Rolling a Generation

Frame 31 of 107

The question that stalls most rollover plans — "which procedure applies to this CA?" — is one goca answers for you. POST /v1/cas/{ca}/rollover (console: the CA card's Rollover action) resolves the mode itself — you are told, not asked:

After cutover, the previous generation moves to rollover state: it stops issuing but keeps signing its own CRLs until its issued population expires.

Two more fields ride the same call. An algorithm in the body switches algorithms at rollover — this is precisely the mechanism a classical→PQC migration rides. And custody moves a key between software, strict provider and wrapped custody — because custody, like the algorithm, is decided when the generation's key is minted and at no other time.

Now I can roll a CA generation — including to a new algorithm — without stopping service.