I'm not sure if this works currently:
- root signers remain the same
- but their keys (ubikeys) change
in this case we should ask the signers to sign with both old and new keys but I think that might not happen. This does work if the new key is "owned" by a different signer