Setting window time for Edge certificate renewal process
search cancel

Setting window time for Edge certificate renewal process

book

Article ID: 372755

calendar_today

Updated On:

Products

VMware VeloCloud SD-WAN

Issue/Introduction

How to set manual window time for edge certification renewal

The auto-renewal process for certificates can be manually set by following the steps below:

Log in to the VCO --> Navigate to Orchestrator --> System Properties --> edge.certificate.renewal.window

Fields to be modified under value:

  • "enabled": true
  • "days": Day of the week for certificate renewal (e.g., Sat)
  • "start": Start time (e.g., 00)
  • "end": End time (e.g., 05)

Example: The above timestamps will renew the edge certificate on Saturday from 00:00  to 05:00 

  • "timezone": local

Note: "Local" refers to the edge's location time zone based on the Geo IP lookup of the WAN link, rather than the time set on the edge itself.

 

 

Note :You can enable these values, but keep in mind that there is a cache involved. All edge certificates should be pushed simultaneously before setting the values.

 

Environment

All Vmware Velocloud Sd-wan on-prem environment

Resolution

The edge certificate renewal process will cause the existing tunnels to flap. By setting it manually, we can plan this during non-production hours.