Skip to content

Fix: Ensure step ca rekey --daemon generates new keys as expected #1441

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

aliamerj
Copy link

Name of feature:

Rekeying with new private key in daemon mode

Description

This PR fixes #1343 where step ca rekey with the --daemon flag was not generating new keys on renewal — behaving like step ca renew instead.

Pain or issue this feature alleviates:

Previously, running step ca rekey ... --daemon would renew the certificate without generating a new key, defeating the purpose of rekeying. This fixes that behavior.

Why is this important to the project (if not answered above):

It ensures rekeying in daemon mode actually rotates the private key, aligning with user expectations and the behavior of one-shot rekeying.

Is there documentation on how to use this feature? If so, where?

Yes

In what environments or workflows is this feature supported?

In what environments or workflows is this feature explicitly NOT supported (if any)?

Supporting links/other PRs/issues:

Fixes: #1343

💔Thank you!

@github-actions github-actions bot added the needs triage Waiting for discussion / prioritization by team label Jun 20, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
needs triage Waiting for discussion / prioritization by team
Projects
None yet
Development

Successfully merging this pull request may close these issues.

[Bug]: step ca rekey does not create new keys when used with the --daemon flag
1 participant