Coupled Rotation - Atomic Execution Sequence
When certificate rotation is triggered alongside key rotation, AppViewX executes both operations as a single, strictly ordered atomic sequence. Each step must succeed before the next begins.
In a coupled rotation, certificate rotation and key rotation are treated as a single indivisible operation. The execution sequence is mandatory and cannot be reordered. If any step fails, the overall rotation fails and no partial state is committed to the endpoint.
What Is Coupled Rotation?
Coupled rotation occurs when a key policy is configured with certificate rotation enabled. In this mode, rotating a key also triggers rotation of the associated SSH certificate on the same endpoint. The two operations are bound together, they succeed together or fail together.
Atomic Execution Sequence
The following steps are executed in strict order during a coupled rotation. Each step must complete successfully before the next begins:
-
Backup existing key and certificate - The current key and its associated certificate are backed up and stored in a secure encrypted format in Recently Rotated Keys. Rotation does not proceed until the backup is confirmed. A confirmation entry is written to the audit log: Backup completed for the <key type> for action <action> with name <key name> with fingerprint <key fingerprint> with group name <key group name> by the user <user name>.
-
Generate new SSH key - A new key is generated according to the key type, size, and algorithm defined in the associated key policy. The new key follows the naming convention
KEYTYPE_TIMESTAMP. -
Issue new SSH certificate - A new certificate is issued for the new key using the Certificate Authority (CA) configured in the policy. This step is executed only after the new key has been successfully generated.
-
Deploy key and certificate to endpoint - The new key and its new certificate are pushed to the target host endpoint together. The old key and certificate are removed from the endpoint as part of this step.
-
Update inventory - The key inventory and certificate records are updated to reflect the newly rotated key and certificate.
Failure Handling
If any step in the atomic sequence fails, the rotation is halted. The following outcomes apply:
-
The endpoint retains the original key and certificate; no partial state is written to the host.
-
The backed-up key is retained in Recently Rotated Keys and can be used to roll back if needed.
-
The failure reason and skipped keys are reported in the Report stage of the workflow under Automation > Service Request > All.
-
Keys with missing file paths are skipped and logged with status Skipped - Missing.
-
Keys whose associated certificate CA is unknown are skipped and logged with status Skipped - Unknown CA.
Triggering a Coupled Rotation
Coupled rotation is triggered from the Key Inventory the same way as a standard key rotation:
- Go to Menu > SSH > Inventory > Key Inventory.
- Select one or more keys that have an associated certificate and a configured CA in their key policy.
- From the Actions dropdown, select Rotate.
- Confirm the rotation in the confirmation dialog. The atomic execution sequence begins immediately.
- To monitor progress and view the report, go to Automation > Service Request > All and select the corresponding request.
Rolling Back a Coupled Rotation
If a coupled rotation completes but results in access issues, you can roll back to the previous key-certificate pair from Recently Rotated Keys:
- Go to Menu > SSH > Inventory > Key Inventory.
- Select Recently Rotated Keys.
- Select the key and choose Rollback from the Actions menu.
- Confirm the rollback. The endpoint is restored to the previous key-certificate pair.
