Key rotation
All commands run in /opt/entrosity/deploy with
docker compose -f docker-compose.prod.yml --env-file .env, abbreviated
dc below.
JWT secret
RMM_JWT_SECRET signs only Axis's event stream tokens, which live one
minute; users' tokens come from Entrosity Hub
(Hub keys).
- Set
RMM_JWT_SECRET_OLDto the currentRMM_JWT_SECRET, andRMM_JWT_SECRETto a new value (openssl rand -base64 32). dc up -d backend. Tokens signed with either key are accepted; new ones use the new key.- After a few minutes, remove
RMM_JWT_SECRET_OLDanddc up -d backendagain.
Nobody is signed out: open event streams reconnect with a new token.
Master key
- Set
RMM_MASTER_KEY_OLDto the current key andRMM_MASTER_KEYto a new one.dc up -d backend: the backends decrypt with both keys and encrypt with the new one. - Re-encrypt the stored secrets:
It re-seals the AD sync credentials and reports what it re-sealed. Run it again if it reports concurrent changes.dc run --rm backend rotate-master-key --dry-rundc run --rm backend rotate-master-key
- Wait until the mail queue is empty (queued e-mails are sealed too;
usually minutes). Then remove
RMM_MASTER_KEY_OLDanddc up -d backend. - Take a new backup. Older backups need the old key.
Entrosity Hub keys
- Signing key (
PLATFORM_JWT_SIGNING_KEY, signs every Hub token): setPLATFORM_JWT_SIGNING_KEY_OLDto the current key andPLATFORM_JWT_SIGNING_KEYto a new one, thendc up -d platform. Both public keys are published; Axis fetches the new one when it first sees itskid. After 15 minutes (the lifetime of the Hub's longest-lived tokens), remove the old key anddc up -d platform. - Master key (
PLATFORM_MASTER_KEY, TOTP secrets and queued e-mails): setPLATFORM_MASTER_KEY_OLDto the current key andPLATFORM_MASTER_KEYto a new one,dc up -d platform, thendc run --rm platform rotate-master-key --dry-runand without--dry-run. Once the mail queue is empty, remove the old key, restart the Hub and take a new backup. - Axis's product token (
PLATFORM_PRODUCT_TOKEN_RMM): change it in.envanddc up -d platform backend(compose passes it to both).
Database passwords
- Owner (
rmm): change it in PostgreSQL (ALTER ROLE), updatePOSTGRES_PASSWORDin.env, thendc up -d. - Application (
rmm_app): changeRMM_APP_DATABASE_PASSWORDand rundc run --rm migrate, which sets it; thendc up -d backend.
MinIO
Change MINIO_ROOT_PASSWORD and restart minio and the backends.
Agent and connector keys
Re-enrolling a machine rotates its key. Decommissioning a device (or deleting a connector) revokes its key everywhere immediately.
Release signing key
Agents trust the public key built into their MSI. Before you replace
RMM_RELEASE_SIGNING_KEY:
- build a release with the new public key (
RELEASE_PUBLIC_KEY); - publish it while the server still signs with the old key, and let it roll out;
- then switch the server to the new signing key.
Agents that miss the transitional release must be reinstalled.
Release token
Set a new RMM_RELEASE_TOKEN on the server and in the repository secret
of the same name, then dc up -d backend.