Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Support CA certificate rotation with cross-signing CA certs #509

Open
sebgl opened this issue Mar 12, 2019 · 0 comments
Open

Support CA certificate rotation with cross-signing CA certs #509

sebgl opened this issue Mar 12, 2019 · 0 comments
Labels
>enhancement Enhancement of existing functionality

Comments

@sebgl
Copy link
Contributor

sebgl commented Mar 12, 2019

When the CA cert is rotated, it might incur downtime on the cluster (unless all nodes keep their existing connections alive, which happens most of the times).

We should deal with it by properly cross-signing the certificate.

See https://github.com/elastic/k8s-operators/blob/master/docs/design/0006-certificate-management.md#avoiding-downtime-during-rotation

@sebgl sebgl added the >enhancement Enhancement of existing functionality label Mar 12, 2019
This was referenced Mar 12, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
>enhancement Enhancement of existing functionality
Projects
None yet
Development

No branches or pull requests

1 participant