nebula certificate expired but node always connected #888
-
hi guys, i checked nebula certificate expired but node always connected only after nebula restart notices the expired certificate: |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 2 replies
-
Hi @luisnodealert - it's true that nodes won't shut down if their own certificate expires. There is a bit of history in why this behavior exists the way it does. Prior to v1.5.0, For this reason, it would be detrimental to your network stability if a host shut itself down while it was still communicating with other hosts. Perhaps you could share a bit about what you're hoping to achieve by having the host shut itself down early? It seems to me that in both cases you're going to struggle with network connectivity issues. Would a log message warning about an expired certificate prior to a shutdown/restart be helpful? |
Beta Was this translation helpful? Give feedback.
-
okay thanks. |
Beta Was this translation helpful? Give feedback.
@luisnodealert if you enable
pki.disconnect_invalid
on all of your hosts, they will tear tunnels down when their peer's host expires.The host with an expired cert will not tear its own tunnels down, nor will it shut itself down as a result of its own certificate expiring.