7.x
/var/lib/kubelet/pki/kubelet.crt
[ /var/lib/kubelet/pki ]# openssl x509 -text -in kubelet.crt
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 2 (0x2)
Signature Algorithm: sha256WithRSAEncryption
Issuer: CN=oms.vio.local-ca@1591484450
Validity
Not Before: Jun 6 22:00:49 2020 GMT
Not After : Jun 6 22:00:49 2021 GMT
Subject: CN=oms.vio.local@1591484450
Subject Public Key Info:
...
On each k8s node (vio-manager and controllers), run the following:
rm /var/lib/kubelet/pki/kubelet.*
systemctl restart kubelet
When kubelet
restarts, if there is no kubelet.crt and kubelet.key present in /var/lib/kubelet/pki/, kubelet
automatically generates a new key and certificate (valid for one year from today).