File: proc_troubleshooting-expired-certificates.adoc

package info (click to toggle)
golang-github-crc-org-crc 2.34.0%2Bds1-2
  • links: PTS, VCS
  • area: main
  • in suites: forky, sid, trixie
  • size: 2,548 kB
  • sloc: sh: 398; makefile: 326; javascript: 40
file content (31 lines) | stat: -rw-r--r-- 1,026 bytes parent folder | download
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
= Troubleshooting expired certificates

The system bundle of {ocp} in each released [command]`{bin}` executable expires 1 year after the release.
This expiration is due to certificates embedded in the {ocp} cluster.
The [command]`{bin} start` command triggers an automatic certificate renewal process when needed.
Certificate renewal can add up to five minutes to the start time of the cluster.

To avoid this additional startup time, or in case of failures in the certificate renewal process, use the following procedure:

.Procedure
To resolve expired certificate errors that cannot be automatically renewed:

. link:{crc-download-url}[Download the latest {prod} release] and place the [command]`{bin}` executable in your `$PATH`.

. Remove the cluster with certificate errors using the [command]`{bin} delete` command:
+
include::partial$snip_crc-delete.adoc[]

. Set up the new release:
+
[subs="+quotes,attributes"]
----
$ {bin} setup
----

. Start the new instance:
+
[subs="+quotes,attributes"]
----
$ {bin} start
----