XCO uses K3s for management of microservices which comes up with its own certificates.
The certificate is valid for 10 years from the date of installation and is regenerated after every upgrade. It supports the following alerts which effects the health of XCO security subsystem:
For more information, see Fault Management - Alerts.
You can renew or regenerate the K3s CA by using either script or command.
To renew or regenerate the K3S CA, use the renewal script efa_k3s_renew_certs.sh.
sudo bash <path to the script>/efa_k3s_renew_certs.sh --type ca
To renew or regenerate the K3S CA, use the efa certificate server renew command.
efa certificate server renew --cert-type
Note
On renewal of the certificate, CertificateRenewalAlert
is raised
which changes the health of the system to green.