# Certificate cattle-webhook-tls expired

**URL:** <https://forums.suse.com/t/certificate-cattle-webhook-tls-expired/21386>\
**Category:** SUSE Rancher Prime\
**Created:** [October 12, 2021, 7:00am UTC](https://forums.suse.com/t/certificate-cattle-webhook-tls-expired/21386 "2021-10-12T07:00:02Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![crazyworlds](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/crazyworlds/32/8103_2.png) [@crazyworlds](https://forums.suse.com/u/crazyworlds)\
**Post date:** [October 12, 2021, 7:00am UTC](https://forums.suse.com/t/certificate-cattle-webhook-tls-expired/21386/1 "2021-10-12T07:00:02Z")

</div>

I realized that the certificate in question has expired.

 ![ran](https://us1.discourse-cdn.com/flex022/uploads/suse/original/2X/4/403dc8bcdc301796a5ae856f812330d08b14b82e.png)

I noticed this because it is no longer possible for me to manage the permissions on the cluster with tis error:

_" Internal error occurred: failed calling webhook “[rancherauth.cattle.io](http://rancherauth.cattle.io)”: Post “[https://rancher-webhook.cattle-system.svc:443/v1/webhook/validation?timeout=10s](https://rancher-webhook.cattle-system.svc:443/v1/webhook/validation?timeout=10s)”: x509: certificate has expired or is not yet valid: current time 2021-10-12T06:55:58Z is after 2021-10-06T08:21:32Z"_

I try to renew all certificate with “rke cert rotate” but without success  
How I can renew this certificate?

---

<div class="post-metadata">

**Author:** ![crazyworlds](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/crazyworlds/32/8103_2.png) [@crazyworlds](https://forums.suse.com/u/crazyworlds)\
**Post date:** [October 12, 2021, 12:43pm UTC](https://forums.suse.com/t/certificate-cattle-webhook-tls-expired/21386/2 "2021-10-12T12:43:49Z")

</div>

Following this issue : [How to rotate cattle-webhook-tls certificate when it has expired? · Issue #35068 · rancher/rancher · GitHub](https://github.com/rancher/rancher/issues/35068)  
I resolved deleting the certificate and redeploy cattle-webhook  
The new certificate was automatly created
