How to renew etcd certificates in OpenShift 4.8 and lower when certificates are already expired and etcd is encrypted
Issue
- How to renew the
etcd
certificates in OpenShift 4.8 and lower when the certificates are already expired? - Kube-apiserver shows in the logs "x509 certificate is not valid".
Check the diagnostics steps of this solution to verify that the etcd certificates are expired.
Environment
-
Red Hat OpenShift Container Platform
- 4.6
- 4.7
- 4.8
-
Etcd is encrypted
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.