Ongoing Renewal Policy for the Root CA Certificate

Adopt a policy of renewing the Root CA certificate in your cluster on a regular basis to decrease the risk of it being compromised.

You can view the age of the current Root CA certificate from the OKM Console, see Show Properties of the Root CA Certificate. You can download the Root CA certificate from the OKM Manager GUI to your workstation, see Save a Client Certificate. When you are ready, you can renew the Root CA certificate, see Renew the Root CA Certificate.