PVE cert renewal failure

antubis

Renowned Member
Apr 20, 2012
27
2
68
Hi,

I have a highly productive PVE cluster (3 nodes) with ceph storage running. Unfortunatly I've accidentally overwritten the pve-ssl.pem and pve-ssl.key (instead of using the -pveproxy files) with our custom certs on installation. Now the custom certs are expiring and of course the pve service can't renew them.

I found the thread https://forum.proxmox.com/threads/solved-pve-certificate-expires-in-more-than-2-years.79152/ with a similar issue and the pvecm updatecerts -f command to recreate the certs with the cluster internal ca.

My question is now... can I just do this in a productively running multi-node cluster with ceph storage without running into problems or even data loss or is there maybe a recommended procedure (stopping/restarting services in an order, etc.)?

Thanks for any help
antubis