# Certificate rotation problems

**URL:** <https://forums.suse.com/t/certificate-rotation-problems/20561>\
**Category:** SUSE Rancher Prime\
**Created:** [June 17, 2021, 3:40pm UTC](https://forums.suse.com/t/certificate-rotation-problems/20561 "2021-06-17T15:40:03Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![tdudgeon](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/tdudgeon/32/7692_2.png) [@tdudgeon](https://forums.suse.com/u/tdudgeon)\
**Post date:** [June 17, 2021, 3:40pm UTC](https://forums.suse.com/t/certificate-rotation-problems/20561/1 "2021-06-17T15:40:03Z")

</div>

Similar to [this post](http://forums.suse.com/t/rotate-self-signed-certificate/17934), I’m having problems connecting to a rancher managed cluster. Kubectl is complaining with:

```auto
Unable to connect to the server: x509: certificate has expired or is not yet valid: current time 2021-06-17T13:47:42+01:00 is after 2021-06-13T10:25:40Z

```

I’ve rotated the certificates for the cluster where rancher is running using `rke cert rotate` and I’ve rotated the certs for the cluster I’m trying to access through the racher ui, but I still get that error.

The cluster seems OK, and in the Rancher UI the cluster manager is working fine, but the new cluster explorer now seems dead with the page showing:

```auto
HTTP Error 500:
from /k8s/clusters/c-7xtkg/v1/schemas

```

What might I have missed?
