You migrate signing keys by publishing new keys ahead of time before they're added to an SP configuration so that by the time it uses the key, the IdPs all have it or have been told about the change. >How we are planning to do certificate rollout? That is not the right process for a signing key. Nor is it correct for an encryption key. -- Scott