<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: self-signed Kubernetes certificate for cluster - ignore certificate validation in Container platforms</title>
    <link>https://community.dynatrace.com/t5/Container-platforms/self-signed-Kubernetes-certificate-for-cluster-ignore/m-p/121184#M374</link>
    <description>&lt;P&gt;FYI this will be a requirement in the near future, Id you can always enable it but then set it to false in the config file as well. But id reach out to support to double check on this and the impacts of it turned on/off&lt;/P&gt;</description>
    <pubDate>Mon, 01 Feb 2021 15:07:14 GMT</pubDate>
    <dc:creator>ChadTurner</dc:creator>
    <dc:date>2021-02-01T15:07:14Z</dc:date>
    <item>
      <title>self-signed Kubernetes certificate for cluster - ignore certificate validation</title>
      <link>https://community.dynatrace.com/t5/Container-platforms/self-signed-Kubernetes-certificate-for-cluster-ignore/m-p/121183#M373</link>
      <description>&lt;P&gt;Hi there, To make cluster connect with Kubernetes, I'm trying to&lt;A href="https://www.dynatrace.com/support/help/shortlink/sgw-proxy-authentication#certificate-management-for-cloud-foundry-kubernetes-and-openshift-communication-" target="_blank" rel="noopener noreferrer"&gt; import the public certificate to trust stores in AGs&lt;/A&gt;. But I keep getting below error:&lt;/P&gt;
&lt;PRE&gt;PS E:\Program Files\dynatrace\gateway\jre\bin&amp;gt; ./keytool.exe -import -file "E:/cert/aks-prod.pem" -alias aksweuprod -keystore "C:/ProgramData/dynatrace/gateway/ssl/trusted.jks"&lt;BR /&gt;Enter keystore password:&amp;nbsp;&lt;BR /&gt;keytool error: java.lang.Exception: Input not an X.509 certificate&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Got to know that kubernete's certificate is &lt;STRONG&gt;self-signed &lt;/STRONG&gt;hence the reason.&lt;/P&gt;
&lt;P&gt;What is the security impact of disabling the certificate validation (referring to screenshot)?&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.dynatrace.com/legacyfs/online/28070-1612183157872.png" border="0" /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jun 2021 12:12:02 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Container-platforms/self-signed-Kubernetes-certificate-for-cluster-ignore/m-p/121183#M373</guid>
      <dc:creator>rswarnka</dc:creator>
      <dc:date>2021-06-09T12:12:02Z</dc:date>
    </item>
    <item>
      <title>Re: self-signed Kubernetes certificate for cluster - ignore certificate validation</title>
      <link>https://community.dynatrace.com/t5/Container-platforms/self-signed-Kubernetes-certificate-for-cluster-ignore/m-p/121184#M374</link>
      <description>&lt;P&gt;FYI this will be a requirement in the near future, Id you can always enable it but then set it to false in the config file as well. But id reach out to support to double check on this and the impacts of it turned on/off&lt;/P&gt;</description>
      <pubDate>Mon, 01 Feb 2021 15:07:14 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Container-platforms/self-signed-Kubernetes-certificate-for-cluster-ignore/m-p/121184#M374</guid>
      <dc:creator>ChadTurner</dc:creator>
      <dc:date>2021-02-01T15:07:14Z</dc:date>
    </item>
  </channel>
</rss>

