This documentation page describes the Kubernetes certificates' expiration check used by the Horizon Cloud Connector, where you can see the expiration warnings, and how the system automatically renews the certificates at the two-month point prior to expiration.
Introduction
As described in KB article 90505, a deployed Horizon Cloud Connector has an internal Kubernetes cluster with system-generated certificates used for secure communication and connectivity with the Horizon control plane. These system-generated certificates have a validity of one year (1 year).
To avoid disruptions to the appliance's communications with the control plane from the system-generated certificates reaching the expiration date prior to renewal, starting with version 2.4, the Horizon Cloud Connector appliance provides:
- Weekly automated checks of the validity of the appliance's Kubernetes certificates
- On-screen display of the current count of days to expiration.
- Automatic renewal of the certificates when the validity check determines that the certificate validity is less than 60 days to expiration. Because the appliance's services have a brief downtime during the renewal process, the system's automatic renewal process occurs only on weekend days at midnight, according to the appliance's local time. The system renews the certificates for one (1) year.
System's Validity Checks
The appliance checks the validity on a weekly basis, on every Saturday and Sunday at midnight according to the appliance's local time.
The validity check assesses the number of days left before the Kubernetes cluster's certificates will expire. If the certificate validity is less than 60 days, the system will automatically renew and issue new certificates with a validity of one (1) year.
When you view the on-screen information, the status is calculated in real time. For example, when you view the displayed information on a week day like Wednesday, the UI displays the number of days remaining to expiration from that Wednesday.
The on-screen information follows a pattern according to the number of days remaining until the expiration date.
-
More than 120 days remaining - Green (good)
The on-screen information displays the number of days that the certificates are valid. For example
valid for 364 days. -
Between 120 and 60 days remaining - Orange (warning)
When the time crosses the eight-month point, the on-screen information displays the number of days to expiration and a link to KB article 90505 for the renewal steps you can take to renew the certificates in advance of the system's automated renewal.
Because the renewal process can cause a brief downtime of the appliance and its services, you might choose to follow the steps in the KB article to renew the certificates yourself instead of waiting until the time advances to within 60 days of expiration. Renewing the certificates yourself allows you to determine the day and time of this brief downtime. As described in the KB article, the procedure includes rebooting the appliance and it might take several minutes for all services to re-initialize.
-
Less than 60 days remaining - Red (error)
When the time is within 60 days of expiration, the on-screen information displays the number of days to expiration and a link to KB article 90505 for the renewal steps you can take to renew the certificates in advance of the system's automated renewal.
The next time the system's validity check runs and determines the certificate's validity is less than 60 days, the system automatically renews and issues new certificates. In the automated renewal, the new certificates have a validity of one (1) year.
On-Screen Locations
The on-screen validity information can be viewed in the following locations:
- In the Horizon Cloud Connector configuration portal, in the Cloud Connector Health list, you can see the on-screen message by hovering over the icon next to the Kubernetes Certificates row.
- If the Active Directory domain registration steps were completed in your first-gen tenant environment, you can use the Horizon Universal Console's Capacity page to navigate to the pod's details page and hover over the icon in that UI page.
此页面对您有帮助吗?