From d78f25ee12d10f132692468d6a083a4bda9df361 Mon Sep 17 00:00:00 2001 From: Alena Prokharchyk Date: Wed, 20 Mar 2019 12:21:46 +1100 Subject: [PATCH] Update _index.md --- .../rke-clusters/certificate-rotation/_index.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/content/rancher/v2.x/en/cluster-provisioning/rke-clusters/certificate-rotation/_index.md b/content/rancher/v2.x/en/cluster-provisioning/rke-clusters/certificate-rotation/_index.md index 1a8848a5d01..6e4d8d1d69b 100644 --- a/content/rancher/v2.x/en/cluster-provisioning/rke-clusters/certificate-rotation/_index.md +++ b/content/rancher/v2.x/en/cluster-provisioning/rke-clusters/certificate-rotation/_index.md @@ -8,7 +8,7 @@ _Available as of v2.2.0_ By default, Kubernetes clusters require certificates and Rancher launched Kubernetes clusters have certificates automatically generated for them. > **Note:** Even though the RKE CLI can use custom certificates for the Kubernetes cluster components, Rancher currently doesn't allow the ability to upload these in Rancher Launched Kubernetes clusters. -When generating certificates, the cluster certificates are set to expire after 1 year and the CA certificate expires after 10 years. Rotating these certificates are important before the certificates expire as well as if a certificate is compromised. +When generating certificates, the cluster certificates are set to expire after 1 year and the CA certificate expires after 10 years. Rotating these certificates is important before the certificates expire as well as if a certificate is compromised. After the certificates are rotated, the Kubernetes components are automatically restarted. Certificates can be rotated for the following services: