Skip to content
Discussion options

You must be logged in to vote

Hi there,

Yes, the claims and minTLSCertDuration only apply to certificates created by the provisioner.

Could you give me a bit more context on your situation, and why you're wanting to change the CA's TLS certificate parameters?

If your subscribers trust the CA certificate, the short-lived leaf certificate generated by the CA should always be trusted.

Replies: 2 comments 4 replies

Comment options

You must be logged in to vote
3 replies
@Jcpetrucci
Comment options

@tashian
Comment options

tashian Nov 4, 2020
Collaborator

@tashian
Comment options

tashian Nov 4, 2020
Collaborator

Answer selected by Jcpetrucci
Comment options

You must be logged in to vote
1 reply
@Jcpetrucci
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants
Converted from issue

This discussion was converted from issue #418 on November 04, 2020 18:38.