When adding custom API server certificate to the Hosted Cluster, the bootstrap-kubeconfig is no longer trusted in RHOCP4

Solution Verified - Updated -

Issue

  • Custom API certificates were rolled out for a Hosted Control Plane (HCP) cluster in RHOCP4, but failing with the following error:

    tls: failed to verify certificate: x509: certificate signed by unknown authority
    
  • Error persists despite root CA is present in /etc/pki/ca-trust/source/anchors/.

Environment

  • Red Hat OpenShift Container Platform (RHOCP)
    • 4

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content