# Custom Kubernetes certificates

**URL:** <https://forums.suse.com/t/custom-kubernetes-certificates/4955>\
**Category:** Rancher 1.x\
**Created:** [December 19, 2016, 8:59pm UTC](https://forums.suse.com/t/custom-kubernetes-certificates/4955 "2016-12-19T20:59:24Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![woutor](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/woutor/32/1961_2.png) [@woutor](https://forums.suse.com/u/woutor)\
**Post date:** [December 19, 2016, 8:59pm UTC](https://forums.suse.com/t/custom-kubernetes-certificates/4955/1 "2016-12-19T20:59:24Z")

</div>

Hi,

I have set up a Kubernetes cluster using Rancher. Now I want to expose my Kubernetes API on a public IP and connect to it using a client certificate.

Now I face the following problems:

To create a client certificate, I need the CA key. However, in the /etc/kubernetes/ssl directory in the kubernetes container, I only find the CA certificate (and the server key and certificate). So my question is, where do I find the CA key?

Furthermore, the current server certificate is not valid for my external IP/DNS. Only for the internal IP’s. So I probably have to create a custom certifcate anyway.

According to [the documentation](http://docs.rancher.com/rancher/v1.2/en/installing-rancher/installing-server/basic-ssl-config/#using-self-signed-certs-beta) I can use my own certificates in Rancher, but my question is whether they will be used by Kubernetes as well?

Finally, how do I change these certificates without reinstalling my current cluster?

Thanking you in advance,  
Wouter

---

<div class="post-metadata">

**Author:** ![juheimbu](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/juheimbu/32/2880_2.png) [@juheimbu](https://forums.suse.com/u/juheimbu)\
**Post date:** [September 27, 2017, 11:17pm UTC](https://forums.suse.com/t/custom-kubernetes-certificates/4955/2 "2017-09-27T23:17:24Z")

</div>

Did you ever get this answered? I’m having the same issue.

Cheers!  
-juheimbu
