Managed Kubernetes
Latest
Frequently Asked Questions
Solutions
How Tos
Internal Only
Templates
Powered By

Title
Message
Create new category
What is the title of your new category?
Edit page index title
What is the title of the page index?
Edit category
What is the new title of your category?
Edit link
What is the new title and URL of your link?
Multiple old CA cert Files Observed on Host After Host CA Rotation
Copy Markdown
Open in ChatGPT
Open in Claude
Problem
- Multiple copies of old/expired certificates of the Platform9 Management Plane continue to exist in /etc/pf9/certs/ca directory even after CA rotation.
- The same issue is faced for hostagent certificates as well that are present in the /etc/pf9/certs/hostagent/ directory.
- The Bouncer container logs that it is no longer able to establish a connection to Keystone to validate the authentication token, example below:
bouncer.log
2023/11/30 18:46:12 authn with credentials: obtain project token from credentials: send keystone request: Post http://localhost:8158/keystone/v3/auth/tokens?nocatalog: EOFEnvironment
- Platform9 Managed Kubernetes - v5.6.8 and Higher
Answer
- Platform9 is aware of this issue and is currently being tracked internally with JIRA - PMK-6262.
Additional Information
- Use the below command to check the certificate details along with expiry date to determine if the DU is serving expired certificate.
Command to check Certificate details.
xxxxxxxxxxopenssl s_client -connnect <DU-URL>:443 -servername "http.v2.<DU-URL>"example-command
xxxxxxxxxxopenssl s_client -connnect example.platform9.net:443 -servername "http.v2.example.platform9.net"VariableType to search · ESC to discard
GlossaryType to search · ESC to discard
InsertType to search · ESC to discard
No matches
Last updated on
Was this page helpful?
Discard Changes
Do you want to discard your current changes and overwrite with the template?
Archive Synced Block
Message
Create new Template
What is this template's title?
Delete Template
Message