-
What would you like to be added?multiple CA's should be trusted by etcd. Why is this needed?as part of our setup we might need etcd clients to connect to etcd via certificates issued by thier own CA. |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment
-
Hey @ssengar - Thanks for raising this question. The normal way I would think about tackling this would be to provide a certificate bundle that includes the root certificates of all the required trusted CAs. The general steps to do that would be something like:
Have you tried an approach like this? Note: There is an active issue around the refreshing of ca bundles for new connections, i.e. zero downtime updates. Refer: #11555. Just something to be aware of. |
Beta Was this translation helpful? Give feedback.
Hey @ssengar - Thanks for raising this question. The normal way I would think about tackling this would be to provide a certificate bundle that includes the root certificates of all the required trusted CAs.
The general steps to do that would be something like:
Have you tried an approach like this?
Note: There is an active issue around the refreshing of ca bundles for n…