Key rotation is super easy, at least if you have a strong consistency database to read from like DNS nameservers. Key revocation is the hard part, for example what happens if you give your nsec to a bunker, and it leaks, how do you recover from that? You can't do that without a Blockchain but it is ...