Skip to content

Key Rotation

WireGuard keys should be rotated periodically. This procedure covers all three tunnels.

When to Rotate

  • Periodically (every 3-6 months)
  • After a suspected compromise
  • When revoking access for a device

Rotation Procedure

Step 1: Generate New Keys

On the client machine (laptop or local VM):

# Generate new keypair
wg genkey | tee /tmp/new_privkey | wg pubkey > /tmp/new_pubkey
echo "New public key: $(cat /tmp/new_pubkey)"

Step 2: Update Server Configuration

On the Strato host, update the peer's public key:

# Get current preshared key from running config
PSK=$(sudo wg show <interface> dump | awk "/<old-pubkey>/{print \$2}")

# Add new peer
echo "$PSK" > /tmp/psk_file
sudo wg set <interface> peer <new-pubkey> \
  preshared-key /tmp/psk_file \
  allowed-ips 10.0.X.2/32
shred -u /tmp/psk_file

# Remove old peer
sudo wg set <interface> peer <old-pubkey> remove

# Update persistent config
sudo sed -i "s|^PublicKey = <old-pubkey>|PublicKey = <new-pubkey>|" \
  /etc/wireguard/<interface>.conf

Step 3: Update Client Configuration

On the client machine:

# Update private key in config
sudo sed -i "s|^PrivateKey = .*|PrivateKey = $(cat /tmp/new_privkey)|" \
  /etc/wireguard/<config>.conf

# Restart interface
sudo wg-quick down <config> && sudo wg-quick up <config>

Step 4: Verify

# Check handshake
sudo wg show <interface>

# Test connectivity
ping -c 2 10.0.X.1

Step 5: Clean Up

shred -u /tmp/new_privkey /tmp/new_pubkey

Important Notes

Live Rotation

Use wg set to apply changes live without restarting the interface. This avoids disconnecting other peers.

Never Expose Private Keys

  • Use shred -u instead of rm for key files
  • Don't paste private keys in chat or logs
  • Don't store keys in version control

PresharedKey Rotation

To rotate PresharedKeys (for post-quantum security):

# Generate new PSK
wg genpsk > /tmp/new_psk

# Update on server
sudo wg set <interface> peer <pubkey> preshared-key /tmp/new_psk

# Update server config file
sudo sed -i "s|^PresharedKey = .*|PresharedKey = $(cat /tmp/new_psk)|" \
  /etc/wireguard/<interface>.conf

# Update client config file
sudo sed -i "s|^PresharedKey = .*|PresharedKey = $(cat /tmp/new_psk)|" \
  /etc/wireguard/<client-config>.conf

# Restart client
sudo wg-quick down <config> && sudo wg-quick up <config>

# Clean up
shred -u /tmp/new_psk