Multiple old CA cert Files Observed on Host After Host CA Rotation

Problem

  • Multiple copies of old/expired certificates of the Platform9 Management Plane continue to exist in /etc/pf9/certs/ca directory even after CA rotation.
  • The same issue is faced for hostagent certificates as well that are present in the /etc/pf9/certs/hostagent/ directory.
  • The Bouncer container logs that it is no longer able to establish a connection to Keystone to validate the authentication token, example below:
bouncer.log
Copy

Environment

  • Platform9 Managed Kubernetes - v5.6.8 and Higher

Answer

  • Platform9 is aware of this issue and is currently being tracked internally with JIRA - PMK-6262.

Additional Information

  • Use the below command to check the certificate details along with expiry date to determine if the DU is serving expired certificate.
Command to check Certificate details.
Copy
example-command
Copy
Type to search, ESC to discard
Type to search, ESC to discard
Type to search, ESC to discard