How to update/rotate CA certificate if using external DB in Tanzu Application SErvice
book
Article ID: 374509
calendar_today
Updated On:
Products
VMware Tanzu Application Service
Issue/Introduction
This KB shows you how to update/rotate CA certificate if you configured Tanzu Application Service to use an external DB
Environment
Tanzu Application Service configured to use an external Database
You can check if you are using an external DB under Ops Manager UI -> TAS Tile -> Databases
Resolution
Here are steps on how you can update/rotate CA certificate if you are using RDS as an external Tanzu Application Service DB:
Please note that this procedure assumes there are no TAS upgrades or Database upgrades and you will only be rotating Database CA Certificates
Generate new CA cert on your external Database. Please refer to you external Database documentation.
Once new CA cert is generated. Add the new cert along with the old certificate under Ops Manager UI -> TAS Tile -> External Database -> Database CA Certificate Field. Please don't remove the old certificate
Click "Apply change" on Ops Manager UI for configuration change to take effect
Once Step 3 is successful, update the CA cert on your external Database and verify if your external Database is healthy
Remove the old certificate under Ops Manager UI -> TAS Tile -> External Database -> Database CA Certificate Field. So only the new certificate is existing
Click "Apply change" on Ops Manager UI for configuration change to take effect