# Unknown certificate about to expire

**URL:** <https://forums.suse.com/t/unknown-certificate-about-to-expire/39490>\
**Category:** SUSE Rancher Prime\
**Created:** [November 18, 2022, 1:36am UTC](https://forums.suse.com/t/unknown-certificate-about-to-expire/39490 "2022-11-18T01:36:47Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![jwilkinson](https://avatars.discourse-cdn.com/v4/letter/j/ecc23a/32.png) [@jwilkinson](https://forums.suse.com/u/jwilkinson)\
**Post date:** [November 18, 2022, 1:36am UTC](https://forums.suse.com/t/unknown-certificate-about-to-expire/39490/1 "2022-11-18T01:36:47Z")

</div>

I’m trying to edit a “local” user’s permissions. Clicking save results in this error:

> Internal error occurred: failed calling webhook “[rancherauth.cattle.io](http://rancherauth.cattle.io)”: Post “[https://rancher-webhook.cattle-system.svc:443/v1/webhook/validation?timeout=10s](https://rancher-webhook.cattle-system.svc:443/v1/webhook/validation?timeout=10s)”: x509: certificate has expired or is not yet valid: current time 2022-11-18T01:27:14Z is after 2022-11-09T18:20:28Z

I have tried deleting the user and recreating them. Interestingly, although the same error pops up, the user is created (just not with the permissions), so I’m assuming it is a two-part process. First, creating the user, and second, assigning permissions. It is (apparently) this second part that is failing.

It is unclear what certificate this is referring to, or how to fix it, or where to look for additional data on how to fix it. The RancherUI indicates a valid certificate that won’t expire for another year, so that must not be the cert.

I’m also suspicious of those URLs. They seem like rancher defaults, and maybe they refer to something internal to K3s, and mean the “local” cluster certs need to be rotated. But, if that is the case, unlike with the other clusters there is no easy way to rotate them, and it is not clear that is the problem anyway.

Any additional information on what this error is and why it is occurring would be appreciated. Thank you!

---

<div class="post-metadata">

**Author:** ![jwilkinson](https://avatars.discourse-cdn.com/v4/letter/j/ecc23a/32.png) [@jwilkinson](https://forums.suse.com/u/jwilkinson)\
**Post date:** [November 28, 2022, 6:24pm UTC](https://forums.suse.com/t/unknown-certificate-about-to-expire/39490/2 "2022-11-28T18:24:46Z")

</div>

I found the certificate in the local k3s cluster:

 ![image](https://us1.discourse-cdn.com/flex022/uploads/suse/original/2X/1/14e3cad3ed9939d1e3cd76bcbd96a2defd4a762e.png)

For this particular instance of an expired cert, this issue provides guidance:

> <https://github.com/rancher/rancher/issues/35068#issuecomment-943691271>
>
> \*\*Rancher Server Setup\*\*
> \- Rancher version: 2.5.8
> \- Installation option (Docke…r install/Helm Chart): Helm Chart
> - If Helm Chart, Kubernetes Cluster and version (RKE1, RKE2, k3s, EKS, etc): EKS 
> \- Proxy/Cert Details: External
> 
> \*\*Information about the Cluster\*\*
> \- Kubernetes version:1.20
> \- Cluster Type (Local/Downstream): Local
> - If downstream, what type of cluster? (Custom/Imported or specify provider for Hosted/Infrastructure Provider): N/A
> \<!--
> \* Custom = Running a docker command on a node
> \* Imported = Running kubectl apply onto an existing k8s cluster 
> \* Hosted = EKS, GKE, AKS, etc
> \* Infrastructure Provider = Rancher provisioning the nodes using different node drivers (e.g. AWS, Digital Ocean, etc)
> \--\>
> 
> \*\*Describe the bug\*\*
> 
> the cluster webhook certificate seems to have expired and all RBAC operations are now blocked with the error message \`Internal error occurred: failed calling webhook "rancherauth.cattle.io": Post "https://rancher-webhook.cattle-system.svc:443/v1/webhook/validation?timeout=10s": x509: certificate has expired or is not yet valid\`
> 
> Culprit seems to be this secret containing webhook tls certificate expiring: 
> !\[image\](https://user-images.githubusercontent.com/1773902/136362504-1b87afe3-e4ca-4c74-bdb0-eb80666fa91d.png)
> 
> \*\*To Reproduce\*\*
>  
> Install Rancher via HELM chart and wait for a year.
> 
> \*\*Result\*\*
> Webhook certificate expires and no instructions from Rancher documentation on how to rotate rancher webhook certificate secret.
> 
> \*\*Expected Result\*\*
> 
> I searched a lot of places looking for instructions on how to rotate the certificate but was not able to find any.
> 
> SURE-3475
> SURE-3737
> SURE-3790
> SURE-3528

Here are the steps:

1. Delete the expired cert (cattle-webhook-tls)
2. Modify rancher-webhook deployment image to **rancher-webhook:v0.1.1** , noting the current version
3. Wait until the cattle-webhook-tls secret is created
4. You may need to scale down the image, then back up, and wait a minute, a few times before it regenerates the cert. Look for the message “Active TLS secret cattle-webhook-tls” in the logs.
5. Switch back the rancher-webhook deployment image version again
