#47 Add hard keyring rotation with document re-encryption

open low · sable · 2026-03-02 23:37 · feature · Phase 3: Keyrings

Comments — 1

sable note 2026-03-02 23:37

Future feature: keyring rotate --hard command that re-encrypts all documents under a keyring with a fresh content key after member removal. This is the only way to truly revoke historical access (cached group keys become useless). Requires: download each blob, decrypt with old content key, re-encrypt with new content key wrapped under new group key, re-upload. Expensive — owner must be online and re-upload every blob. Layers on top of #87 (key history).

Generated 2026-03-03 02:53 UTC