Skip to content

Commit c445ec1

Browse files
tete17wozniakjan
andauthored
fix(cert-manager): Ensure there is at least one leaf certificate renewal when renewing the CA (#712)
* fix(cert-manager): Ensure there is at least one leaf certificate renewal when renewing the CA The renewBefore value for the root ca was simply too low barely giving the leaf certificate any time to renew itself. This leads to the root ca expiring before the leaf certificates expires. By removing the renewBefore values we go back to the 2/3 default and as long as the leaf certificate is only valid for half of the root it should be fine. Signed-off-by: Miguel Sacristán Izcue <[email protected]> * set default `renewBefore` for CA to one third of duration Signed-off-by: Jan Wozniak <[email protected]> --------- Signed-off-by: Miguel Sacristán Izcue <[email protected]> Signed-off-by: Jan Wozniak <[email protected]> Co-authored-by: Jan Wozniak <[email protected]>
1 parent 3ad2830 commit c445ec1

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

keda/templates/cert-manager/self-ca.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -13,8 +13,8 @@ spec:
1313
privateKey:
1414
algorithm: RSA
1515
size: 2048
16-
duration: 8760h0m0s # 1 year
17-
renewBefore: 720h0m0s # 1 month
16+
duration: 43800h0m0s # 5 years
17+
renewBefore: 14600h0m0s # 1.6 year, 1/3rd of the duration
1818
issuerRef:
1919
name: {{ .Values.operator.name }}-selfsigned-issuer
2020
kind: Issuer

0 commit comments

Comments
 (0)