Coupled Rotation - Atomic Execution Sequence

When certificate rotation is triggered alongside key rotation, AppViewX executes both operations as a single, strictly ordered atomic sequence. Each step must succeed before the next begins.

In a coupled rotation, certificate rotation and key rotation are treated as a single indivisible operation. The execution sequence is mandatory and cannot be reordered. If any step fails, the overall rotation fails and no partial state is committed to the endpoint.

What Is Coupled Rotation?

Coupled rotation occurs when a key policy is configured with certificate rotation enabled. In this mode, rotating a key also triggers rotation of the associated SSH certificate on the same endpoint. The two operations are bound together, they succeed together or fail together.

Note: Certificates whose Certificate Authority (CA) is unknown at the time of rotation are skipped. They are not removed from the endpoint and are listed in the Report stage of the workflow with the status Skipped - Unknown CA.

Atomic Execution Sequence

The following steps are executed in strict order during a coupled rotation. Each step must complete successfully before the next begins:

  1. Backup existing key and certificate - The current key and its associated certificate are backed up and stored in a secure encrypted format in Recently Rotated Keys. Rotation does not proceed until the backup is confirmed. A confirmation entry is written to the audit log: Backup completed for the <key type> for action <action> with name <key name> with fingerprint <key fingerprint> with group name <key group name> by the user <user name>.

  2. Generate new SSH key - A new key is generated according to the key type, size, and algorithm defined in the associated key policy. The new key follows the naming convention KEYTYPE_TIMESTAMP.

  3. Issue new SSH certificate - A new certificate is issued for the new key using the Certificate Authority (CA) configured in the policy. This step is executed only after the new key has been successfully generated.

  4. Deploy key and certificate to endpoint - The new key and its new certificate are pushed to the target host endpoint together. The old key and certificate are removed from the endpoint as part of this step.

  5. Update inventory - The key inventory and certificate records are updated to reflect the newly rotated key and certificate.

Important: The sequence above is fixed and cannot be reordered. Steps 2, 3, and 4 form an atomic unit. If the certificate issuance (Step 3) fails, the newly generated key is not deployed and the endpoint retains its existing key-certificate pair.

Failure Handling

If any step in the atomic sequence fails, the rotation is halted. The following outcomes apply:

  • The endpoint retains the original key and certificate; no partial state is written to the host.

  • The backed-up key is retained in Recently Rotated Keys and can be used to roll back if needed.

  • The failure reason and skipped keys are reported in the Report stage of the workflow under Automation > Service Request > All.

  • Keys with missing file paths are skipped and logged with status Skipped - Missing.

  • Keys whose associated certificate CA is unknown are skipped and logged with status Skipped - Unknown CA.

Triggering a Coupled Rotation

Coupled rotation is triggered from the Key Inventory the same way as a standard key rotation:

  1. Go to Menu > SSH > Inventory > Key Inventory.
  2. Select one or more keys that have an associated certificate and a configured CA in their key policy.
  3. From the Actions dropdown, select Rotate.
  4. Confirm the rotation in the confirmation dialog. The atomic execution sequence begins immediately.
  5. To monitor progress and view the report, go to Automation > Service Request > All and select the corresponding request.
CAUTION: Rotating keys can result in access loss and authentication problems if AppViewX does not have access to all infrastructure information. Ensure that proper backup and alternative authentication methods are in place before proceeding.

Rolling Back a Coupled Rotation

If a coupled rotation completes but results in access issues, you can roll back to the previous key-certificate pair from Recently Rotated Keys:

  1. Go to Menu > SSH > Inventory > Key Inventory.
  2. Select Recently Rotated Keys.
  3. Select the key and choose Rollback from the Actions menu.
  4. Confirm the rollback. The endpoint is restored to the previous key-certificate pair.