# Error running installation script (the certificate has expired for etcd-server)

**URL:** <https://community.replicated.com/t/error-running-installation-script-the-certificate-has-expired-for-etcd-server/648>\
**Category:** Troubleshooting\
**Created:** [January 4, 2022, 5:19pm UTC](https://community.replicated.com/t/error-running-installation-script-the-certificate-has-expired-for-etcd-server/648 "2022-01-04T17:19:28Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Zeyuan\_Shang](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.replicated.com/zeyuan_shang/32/328_2.png) [@Zeyuan\_Shang](https://community.replicated.com/u/Zeyuan_Shang)\
**Post date:** [January 4, 2022, 5:19pm UTC](https://community.replicated.com/t/error-running-installation-script-the-certificate-has-expired-for-etcd-server/648/1 "2022-01-04T17:19:28Z")

</div>

Hi,  
We were running the script and got this error. Any idea of how to fix this? Thanks!

 ![Screen Shot 2022-01-04 at 12.17.09 PM](https://canada1.discourse-cdn.com/flex030/uploads/replicated/original/1X/1fa6aa7a82080105206de67e87f61085ac08df38.png)

---

<div class="post-metadata">

**Author:** ![Jalaja\_Ganapathy](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.replicated.com/jalaja_ganapathy/32/268_2.png) [@Jalaja\_Ganapathy](https://community.replicated.com/u/Jalaja_Ganapathy)\
**Post date:** [January 4, 2022, 5:51pm UTC](https://community.replicated.com/t/error-running-installation-script-the-certificate-has-expired-for-etcd-server/648/2 "2022-01-04T17:51:59Z")

</div>

Would you be able capture the output ? The Screenshot image is not getting loaded.

This page talks about Certificate renewal - [https://kurl.sh/docs/install-with-kurl/setup-tls-certs#manual-renewal](https://kurl.sh/docs/install-with-kurl/setup-tls-certs#manual-renewal)

jalaja

---

<div class="post-metadata">

**Author:** ![Zeyuan\_Shang](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.replicated.com/zeyuan_shang/32/328_2.png) [@Zeyuan\_Shang](https://community.replicated.com/u/Zeyuan_Shang)\
**Post date:** [January 4, 2022, 6:22pm UTC](https://community.replicated.com/t/error-running-installation-script-the-certificate-has-expired-for-etcd-server/648/3 "2022-01-04T18:22:42Z")

</div>

Thanks. It is  
error execution phase certs/etcd-server: failed to write or validate certificate “etcd-server”? failure loading etcd/server certificate: failed to load certificate: the certificate has expired

---

<div class="post-metadata">

**Author:** ![Zeyuan\_Shang](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.replicated.com/zeyuan_shang/32/328_2.png) [@Zeyuan\_Shang](https://community.replicated.com/u/Zeyuan_Shang)\
**Post date:** [January 5, 2022, 3:59pm UTC](https://community.replicated.com/t/error-running-installation-script-the-certificate-has-expired-for-etcd-server/648/4 "2022-01-05T15:59:46Z")

</div>

Wondering if we rerun a latest kURL script, would that resolve this issue? This is a on-prem deployment therefore we cannot verify it at our side first.

---

<div class="post-metadata">

**Author:** ![laverya](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.replicated.com/laverya/32/263_2.png) [@laverya](https://community.replicated.com/u/laverya)\
**Post date:** [January 5, 2022, 4:11pm UTC](https://community.replicated.com/t/error-running-installation-script-the-certificate-has-expired-for-etcd-server/648/5 "2022-01-05T16:11:54Z")

</div>

Would you be able to provide any extra info about the error message? Sometimes the surrounding lines can help a lot, as can what version of k8s was running.

Generally though, following the steps in the manual cert renewal document (`kubeadm alpha certs renew all`, `mv /etc/kubernetes/manifests/kube-apiserver.yaml /tmp/ && sleep 1 && mv /tmp/kube-apiserver.yaml /etc/kubernetes/manifests/`, `mv /etc/kubernetes/manifests/kube-controller-manager.yaml /tmp/ && sleep 1 && mv /tmp/kube-controller-manager.yaml /etc/kubernetes/manifests/`, `mv /etc/kubernetes/manifests/kube-scheduler.yaml /tmp/ && sleep 1 && mv /tmp/kube-scheduler.yaml /etc/kubernetes/manifests/`) will do the trick for expired certificates.

---

<div class="post-metadata">

**Author:** ![Zeyuan\_Shang](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.replicated.com/zeyuan_shang/32/328_2.png) [@Zeyuan\_Shang](https://community.replicated.com/u/Zeyuan_Shang)\
**Post date:** [January 6, 2022, 4:07am UTC](https://community.replicated.com/t/error-running-installation-script-the-certificate-has-expired-for-etcd-server/648/6 "2022-01-06T04:07:42Z")

</div>

It works now! Thanks so much!
