Renewing a Certificate Authority
Renew a certificate authority (CA) when it nears expiration, whenever you need to update its certificate contents, or if it's been revoked because of a security breach of its certificate or its key.
Renewing a certificate authority creates another certificate authority version with new certificate contents and a new validity period. certificate authority renewals happen manually. You can't automatically renew a certificate authority by using renewal rules. Before you renew a certificate authority, rotate the key that you use with the certificate authority to ensure that the new certificate authority version you create contains updated key material. For more information, see Rotating a Vault Key.