This is a cache of https://docs.openshift.com/container-platform/4.9/virt/node_maintenance/virt-automatic-certificates.html. It is a snapshot of the page at 2024-11-22T19:33:54.509+0000.
Automatic renewal of TLS <strong>certificate</strong>s - Node maintenance | Virtualization | OpenShift Container Platform 4.9
×

All TLS certificates for OpenShift Virtualization components are renewed and rotated automatically. You are not required to refresh them manually.

TLS certificates automatic renewal schedules

TLS certificates are automatically deleted and replaced according to the following schedule:

  • KubeVirt certificates are renewed daily.

  • Containerized Data Importer controller (CDI) certificates are renewed every 15 days.

  • MAC pool certificates are renewed every year.

Automatic TLS certificate rotation does not disrupt any operations. For example, the following operations continue to function without any disruption:

  • Migrations

  • Image uploads

  • VNC and console connections