Cert Renewal related

Last published : Aug 25, 2026
  1. If Prometheus is configured and if after the external CA certificate is renewed, the pod monitor fails to come up. Delete the prometheus cert secret followed by deletion of all pods in the monitored namespace. Prometheus pods then come up.
  2. If the following error message is logged:
    x509: certificate has expired or is not yet valid: current time
    <timestamp1> is after <timestamp2>
    • If you are using an External CA certificate and the certificate has expired. See 'Renewing with an External CA certificate' and renew the certificate.
    • If you are using a self-signed CA, delete the infoscale-CA secret and wait for 10 minutes. Delete the secrets of all the client certificates.
    1. If one of the following error messages is logged:
    error:veritas:tls parseCertsCertificate
                    expired :/etc/vx/\<component name\>/certs/tls.crt
or
tls : bad certificate
  • If you are using an External CA certificate and the certificate has expired. See 'Renewing with an External CA certificate' and renew the certificate. If the certificate has not expired, delete all secrets of the client certificates.
  • If you are using a self-signed CA and the certificate has expired, delete the infoscale-CA secret and wait for 10 minutes. Delete the secrets of all the client certificates. If the certificate has not expired, delete the secrets of all the client certificates.
Related information