Apiservice shows expired certificate
search cancel

Apiservice shows expired certificate

book

Article ID: 388485

calendar_today

Updated On:

Products

VMware Telco Cloud Automation

Issue/Introduction

You will see kube-apiserver logs similar to below snippet:

"Unable to authenticate the request" err="[x509: certificate has expired or is not yet valid: current time 2025-01-12T09:58:59Z is after 2024-09-11T11:16:05Z, verifying certificate SN=#####, SKID=, AKID=AA:AA:##:##:##:##:##:##:##:XX:YY:ZZ:...:## failed: x509: certificate has expired or is not yet valid: current time 2025-01-01T01:00:00Z is after 2024-09-11T11:16:05Z]"

Environment

TCA 2.3

VMware Tanzu Kubernetes Grid 1.x & 2.x

Resolution

  • Verify certificate status of kapp, kube-apiserver or kubelet
  • To verify Kapp certificate, refer
  • To verify Kube-apiserver certificate:
  • To verify Kubelet certificate:
  • If all the certificates are valid and not expired, and you still receive a log snippet stating "expired certificate" in api server log then some application certificate would have got expired which is utilizing api service.
  • To fix, contact application owner to remove their expired certificate.