To rotate simply collect threshold of shares
Or fully regenerate from nsec (effectively a rotation) View quoted note โ
Login to reply
Replies (8)
Is there a way to revoke the old keys?
So no revocation then? You just need the original master key to rotate.
A rotation will invalidate the old keyset (effectively same thing as revocation)
This could still be useful.
Like how an XPUB allows you to use your wallet without pulling out your seed or keeping it in an insecure place, this could allow you to keep your master key somewhere safe while you simply use its derivatives.
If you can put one of the keys on a secure platform where deletions are guaranteed, (thinking 2-of-2 multisig) then if your personal key is compromised, then you can re-initialise your setup.
Maybe... ๐ค
Maybe I need to read more about how frost works.
How does that work, documentation?
This documentation seems to decribe it more (answering my own question, partially):
Understanding FROST - The ZF FROST Book
From my understanding, 'invalidate' or 'revocation' are not the best descriptors. The old keys could still produce a valid signature, it's just that the participants, with new keys, choose to no longer use the older keys, though they may still be stored. That refreshing of the keys wouldn't however require a new public key to verify.