1 Answer
- Newest
- Most votes
- Most comments
0
Hi. The certificate is a convenient vehicle for the client to verify [using standard SSL tools] that it is talking to its own cluster, before sending across login credentials. There is no mechanism to rotate the cluster certificate, as the HSM has no notion of a root CA or chain of trust. The customer CA key pair IS that root of trust from the clusters point of view. Therefore, there is no signficance to the certificate expiring and the expiry date is not checked in our stack.
answered 3 years ago
Relevant content
- AWS OFFICIALUpdated 3 years ago
