Uploaded image for project: 'OpenShift Etcd'
  1. OpenShift Etcd
  2. ETCD-535

Manual CA rotation should rotate all leaf certs

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Done
    • Icon: Undefined Undefined
    • None
    • None
    • None
    • Strategic Product Work
    • 5
    • False
    • None
    • False
    • OCPSTRAT-1104 - [etcd] manual rotation of etcd signer certs when the cluster is still online
    • ETCD Sprint 250

      After merging ETCD-512, we need to ensure the certs are regenerated when the signer changes.

      Current logic in library-go only changes when the bundle is updated, which is not sufficient of a criteria for the etcd rotation. 

      Some initial take: https://github.com/openshift/library-go/pull/1674

      discussion in: https://redhat-internal.slack.com/archives/CC3CZCQHM/p1706889759638639

       

      AC:

       

              tjungblu@redhat.com Thomas Jungblut
              tjungblu@redhat.com Thomas Jungblut
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: