Uploaded image for project: 'Red Hat Advanced Cluster Management'
  1. Red Hat Advanced Cluster Management
  2. ACM-3169

Support certificates rotation

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Done
    • Icon: Undefined Undefined
    • None
    • None
    • Server Foundation, xCM
    • No

      Value Statement

      we need to handle the cert rotation. We cannot just remove the certs dir and regenerate all the certificates, because there are some long-lived certs and CAs that shouldn't be swapped. e.g.:

      1. kube-apiserver serving certificate CAs - if you're connecting from the outside, the CA swap would likely be confusing
      2. system:admin client certificate - we don't want to rotate the certificate that allows you to authenticate to the API

      Definition of Done for Engineering Story Owner (Checklist)

      • ...

      Development Complete

      • The code is complete.
      • Functionality is working.
      • Any required downstream Docker file changes are made.

      Tests Automated

      • [ ] Unit/function tests have been automated and incorporated into the
        build.
      • [ ] 100% automated unit/function test coverage for new or changed APIs.

      Secure Design

      • [ ] Security has been assessed and incorporated into your threat model.

      Multidisciplinary Teams Readiness

      Support Readiness

      • [ ] The must-gather script has been updated.

       

       

              yuyao@redhat.com Yuchen Yao (Inactive)
              clyang82 Chunlin Yang
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: