Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Improve support for rotating the default self-signed certs #7032

Merged
merged 2 commits into from
Mar 13, 2023

Conversation

brandond
Copy link
Member

@brandond brandond commented Mar 7, 2023

Proposed Changes

While writing docs for self-signed cert CA rotation, I realized it really needs its own script. There's also a tweak to the client and server certs and rotate-ca validation checks that we can make to avoid having to restart all the pods after rotating the default self-signed CA certs.

  • Update/rename certs.sh to add support for openssl v1.0
  • Add default cert rotation script
  • Add support for rotating the default self-signed certs

Types of Changes

enhancement

Verification

See docs

Testing

Linked Issues

User-Facing Change

The `k3s certificate rotate-ca` checks now support rotating self-signed certificates without the `--force` option.

Further Comments

@brandond brandond requested a review from a team as a code owner March 7, 2023 23:09
@brandond brandond force-pushed the more_cert_scripts branch 4 times, most recently from 092edb6 to a8757e1 Compare March 8, 2023 01:10
@brandond brandond changed the title Update CA certificate management scripts Improve support for rotating the default self-signed certs Mar 8, 2023
@brandond brandond force-pushed the more_cert_scripts branch 3 times, most recently from 0119333 to 74804b6 Compare March 8, 2023 08:53
Signed-off-by: Brad Davidson <brad.davidson@rancher.com>
We need to send the full chain in order for cross-signing to work
properly during switchover to a new root.

Signed-off-by: Brad Davidson <brad.davidson@rancher.com>
@brandond brandond merged commit 977a855 into k3s-io:master Mar 13, 2023
@brandond brandond deleted the more_cert_scripts branch June 6, 2024 21:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants