Re: Rotating cf-deployment certificates
Mike Youngstrom <youngm@...>
Thanks for the heads up David. I have questions about the rotation process. Although all applications may remain up while re-deploying I imagine things like loggregator will stop working mid deploy when doppler and metron certs no longer match. Perhaps reps will be unable to properly drain when their certs don't match?
Does that sound correct? Is the expiration default the same for certificates created by credhub? Are you aware of any way to increase the default expiration date for credhub or bosh-cli? Long term are core teams working towards zero downtime cert rotation capabilities? Or do you foresee the need to rotate with some service impact an issue long term? Thanks, Mike On Fri, Mar 2, 2018 at 11:32 AM, David Sabeti <dsabeti@...> wrote:
|
|