Skip to main content

Rotate the NodeVault key

Rotating makes a new NodeVault key and has your nodes re-seal every NodeVault secret under it. The old key stays on your nodes as a previous key until you retire it. Jaah never sees the secrets while this happens.

Rotating does not protect you if your current key was exposed, because the new key travels wrapped under the current one. If you think a key leaked, re-enter each secret, or change it with the service it belongs to. See How NodeVault works.

Requires the Org Owner or Org Admin role, NodeVault already set up (see Set up NodeVault), and at least one node online that holds the current key.

Rotate​

Rotation has six steps: Key, Backup, Distribute, Migrate, Rekey and Result.

  1. In the sidebar, select Settings, then NodeVault. Select Rotate key.
  2. On New key, select Generate, then Generate key, or Upload backup to use a key you backed up but never used here; then the Backup step is skipped. Your current key is refused.
  3. On Backup, type and repeat a Passphrase of at least 12 characters, select Download backup, tick I stored the backup; Jaah cannot recover it, and select Next. Keep this backup: it is the only copy of the new key outside your nodes.
  4. On Distribute, select Send key. The new key goes to each node wrapped under your current key, so only nodes that already hold it can open it.
  5. On Migrate, move credentials that aren't in NodeVault yet straight onto the new key, or select Skip.
  6. On Rekey, wait while a node that holds both keys re-seals each secret. Rekeyed counts them. If it says Waiting for a node that holds both keys to come online, start one and the rekey continues.
  7. On Result, check Nodes with the new key, Rekeyed, Not rekeyed, and, if you moved credentials, Moved to NodeVault, Skipped and Failed to move. Then select Done.

The new key is now the Current key. The old one is listed under Previous keys with the number of credentials still using it.

Retire the old key​

Retire a previous key once nothing uses it. Retiring deletes it from every node and can't be undone.

  1. In Settings, then NodeVault, find the key under Previous keys.
  2. If the line under it says a credential still uses this key, open that credential and re-enter its secrets, or wait for the rekey to finish.
  3. Select Retire. In Retire key?, select Retire.
  4. The key shows Retiring until every node has deleted it. A node that is offline confirms when it reconnects.

Select Audit on the NodeVault screen to see every step of the rotation in the audit log.