yes, xcatconfig -c will regenerate the certificate files

/etc/xcat/cert/*
/etc/xcat/ca/*
/root/.xcat/

for the script  /opt/xcat/share/xcat/scripts/setup-xcat-ca.sh, user needs
to pass in the cert name.


Thanks,

Casandra Qiu
...................................................................
Casandra Hong Qiu
Phone: (845) 433-9291, t/l 293-9291
Office: Building 8, 3-B-04
cxh...@us.ibm.com





From:   Russ Auld <russa...@comcast.net>
To:     xCAT-Users <xcat-user@lists.sourceforge.net>
Date:   04/20/2020 09:26 PM
Subject:        [EXTERNAL] [xcat-user] Expired CA cert



The xCAT CA certificate "/etc/xcat/certs/ca.pem" has expired on our MN.
What's the proper procedure to regenerate the SSL certificates?

xcatconfig -c ?

I found this discussion
https://xcat-docs.readthedocs.io/en/stable/advanced/security/certs.html

It looks like I could regenerate the CA cert with
/opt/xcat/share/xcat/scripts/setup-xcat-ca.sh

_______________________________________________
xCAT-user mailing list
xCAT-user@lists.sourceforge.net
https://urldefense.proofpoint.com/v2/url?u=https-3A__lists.sourceforge.net_lists_listinfo_xcat-2Duser&d=DwICAg&c=jf_iaSHvJObTbx-siA1ZOg&r=n1LR_Py9TQX0dVqfGTbLHUMGx25-C8VtBDS0nCzyNXY&m=89fTjsjse5VvB1pOyRSMQ5uSaO6qDMRmObVpXWxHAyQ&s=ehAZj9WC3F-bMF3zPDTVi_536PEMQIgPAXD1yeb8RIc&e=



_______________________________________________
xCAT-user mailing list
xCAT-user@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/xcat-user

Reply via email to