You need to ensure that all of the recovery agent certificates can be used to recover all new private keys