Why does rotating the services/tls_ca certificate require an Apply Change for all tiles in Opsman.
search cancel

Why does rotating the services/tls_ca certificate require an Apply Change for all tiles in Opsman.

book

Article ID: 378758

calendar_today

Updated On:

Products

VMware Tanzu Application Service

Issue/Introduction

Users may want to why performing an Apply Change in Opsman is required when rotating their services/tls_ca certificate.

Resolution

The reason users are required to perform an Apply Change in Opsman for the services/tls_ca certificate is because various environment services (such as Healthwatch, appMetric, Splunk, Service Instances, etc) and internal components (such as GoRouter, Diego Cells, CC's) rely on this cert for secure communication. The user must select all tiles for the Apply Changes so that the new services/tls_ca gets propagated across all tiles, services and deployments.


VMware recommends users refer to the Official Docs for rotating the services/tls_ca certificate.

Additional Information

For more information regarding application behavior while rotating /services/tls_ca leaf certs:

 

For more information regarding why rotating the /services/tls_ca certificate triggers gorouter and diego_cell updates:

 

For more information on how to rotate an already expired /services/tls_ca certificate: