You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
CA-399260: Keep both new and old certs during the switchover (#6223)
In host-refresh-server-certificate, host generates and applies new pool
certificate after stunnel restart. There is 5s that other hosts don't
trust the new certificate. Then operations related with xapi:pool SNI
tls connection will fail. Both the old and new certificates shall be
trusted during the switchover to avoid this. At the end of the refresh
procedure, remove_stale_cert will rename the new pem to pem and update
ca bundle.
0 commit comments