Renewing the management-ca with the ManagementSecretRotation CR
Use the ManagementSecretRotation CR to renew the
management-ca certificate and all end-entity certificates that
management-ca signs.
About this task
Applying the ManagementSecretRotation CR (Custom Resource) is the recommended
method for renewing the management-ca and all its end-entity certificates. The
alternative method is to manually renew the management-ca certificate and then each
of its end-entity certificates, which you can identify from the certificates table Management certificates.
Restriction: The
ManagementSecretRotation CR is for use with a single
data center deployment. Do not attempt to use it with a two data center disaster recovery deployment. See Renewing certificates in a two data center deployment on Kubernetes and OpenShift.