Skip to content

How to rotate ca cert with new root and --force #5613

Discussion options

You must be logged in to vote

generate-custom-ca-certs does not output a new token.

yes, generate-custom-ca-certs was intended to be used before initial cluster startup. Using that that to switch from the default self-signed certs, to custom certs, is not something that we've tested. You'll need to calculate the hash yourself, and update the hash in the token files by hand.

Replies: 2 comments 13 replies

Comment options

You must be logged in to vote
2 replies
@nonessentialprototype
Comment options

@brandond
Comment options

Answer selected by dereknola
Comment options

You must be logged in to vote
11 replies
@brandond
Comment options

@nonessentialprototype
Comment options

@hdong69
Comment options

@nonessentialprototype
Comment options

@hdong69
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants