Skip to content

nebula certificate expired but node always connected #888

Closed Answered by johnmaguire
luisnodealert asked this question in Q&A
Discussion options

You must be logged in to vote

@luisnodealert if you enable pki.disconnect_invalid on all of your hosts, they will tear tunnels down when their peer's host expires.

The host with an expired cert will not tear its own tunnels down, nor will it shut itself down as a result of its own certificate expiring.

Replies: 2 comments 2 replies

Comment options

You must be logged in to vote
2 replies
@luisnodealert
Comment options

@johnmaguire
Comment options

Answer selected by IanVS
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants