Abstract
Optimal PKI life cycle management depends directly on the strategy to deal with the update and replacement of CA certificates and CA private keys. To reach optimal strategy, it is necessary to develop methods that the replacement is executed to match the specific needs of each PKI. Only one strategy is defined in RFC~4210, but real PKIs need a variety of different strategies. This paper classifies these strategies and presents the corresponding procedures to replace certificates and private keys.