Proxy certificate expiration

The CA administrator configures the expiration term for proxy certificates before they can be used by Red Hat OpenShift Container Platform or RHCOS.

The user sets the expiration term of the user-provided trust bundle.

The default expiration term is defined by the CA certificate itsself. The CA administrator must configure the default expiration term for the certificate before the certificate can be used by Red Hat OpenShift Container Platform or RHCOS.

Note

Red Hat does not monitor when CAs expire. Due to the long life of the CAs, this is generally not an issue. However, you might need to periodically update the trust bundle.