Galley is not using the new certificate after rotation in OCP 4

Solution Verified - Updated -


  • Why when creating functionalities in the mesh the following error is thrown?

    $ oc apply -n bookinfo -f bookinfo-gateway.yaml
    Error from server (InternalError): error when creating "bookinfo-gateway.yaml": Internal error occurred: failed calling webhook "": Post "https://istio-galley.istio-system-v1.svc:443/admitpilot?timeout=30s": x509: certificate has expired or is not yet valid: current time 2021-07-16T10:12:48Z is after 2021-07-16T08:33:02Z
  • Galley certificate has expired.

  • Why Galley is not using the renewed certificate?


  • Red Hat OpenShift Container Platform (RHOCP)
    • 4.x
  • Red Hat OpenShift Service Mesh
    • 1.1.x

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content