Chapter 5. Operations 125
5.5.4 Renewing (rekeying) a certificate with a new private key
When you renew a certificate by using a new private key, retire the private key and replace it
with a new one. This process is called certificate rekeying or key rollover. This option prevents
the overuse of a private key. The more a key is used, the more susceptible it is to being
hacked.
All information in the renewed certificate is updated to reflect the renewal, including the key
ring connection information. After you retire and replace the old certificate, you can begin to
use the new certificate and its private key. You can continue to use the old, retired certificate
until it expires to verify previously generated signatures. However, you cannot use ...