# kURL: How to manually rotate an expired certificate for Envoy

**URL:** <https://community.replicated.com/t/kurl-how-to-manually-rotate-an-expired-certificate-for-envoy/889>\
**Category:** Supporting your customers\
**Tags:** kurl, contour, envoy, certificates, tls\
**Created:** [July 26, 2022, 4:05pm UTC](https://community.replicated.com/t/kurl-how-to-manually-rotate-an-expired-certificate-for-envoy/889 "2022-07-26T16:05:37Z")\
**Posts on this page:** 1\
**Showing post:** 1

<div class="post-metadata">

**Author:** ![diamon\_w](https://yyz2.discourse-cdn.com/flex030/user_avatar/community.replicated.com/diamon_w/32/150_2.png) [@diamon\_w](https://community.replicated.com/u/diamon_w)\
**Post date:** [July 26, 2022, 4:05pm UTC](https://community.replicated.com/t/kurl-how-to-manually-rotate-an-expired-certificate-for-envoy/889/1 "2022-07-26T16:05:37Z")

</div>

In a kURL installation using Contour, the default generated Envoy certificate expires in a year. In versions of EKCO less than v0.15.0, this certificate was not rotated automatically.

You can verify the expiration of the current Envoy certificate with:

```auto
for pod in $(kubectl get pods -n projectcontour -l app=envoy -o=name)
do
   echo $pod
   echo ===============
   echo ca.crt:
   kubectl exec $pod -n projectcontour -c envoy -- openssl x509 -enddate -noout -in /certs/ca.crt
   echo tls.crt:
   kubectl exec $pod -n projectcontour -c envoy -- openssl x509 -enddate -noout -in /certs/tls.crt
done

```

Use the following steps to rotate this certificate manually:

1. Delete the secret that holds the gRPC TLS keypair

2. Backup the existing Contour certificate generation job to a file

3. Create a filed named `contour-certgen-<version>.yaml` with the contents of the following YAML replacing `<version>` with your version of contour

```auto
apiVersion: batch/v1
kind: Job
metadata:
  name: contour-certgen-<version>
  namespace: projectcontour
spec:
  template:
    metadata:
      labels:
        app: "contour-certgen"
    spec:
      containers:
      - name: contour
        image: projectcontour/contour:<version>
        imagePullPolicy: IfNotPresent
        command:
        - contour
        - certgen
        - --kube
        - --incluster
        - --overwrite
        - --secrets-format=compact
        - --namespace=$(CONTOUR_NAMESPACE)
        env:
        - name: CONTOUR_NAMESPACE
          valueFrom:
            fieldRef:
              fieldPath: metadata.namespace
      restartPolicy: Never
      serviceAccountName: contour-certgen
      securityContext:
        runAsNonRoot: true
        runAsUser: 65534
        runAsGroup: 65534
  parallelism: 1
  completions: 1
  backoffLimit: 1

```

1. Delete the existing Contour certgen job

2. Apply the new YAML to the cluster

3. Restart Contour/Envoy

---

_[View the full topic](https://community.replicated.com/t/kurl-how-to-manually-rotate-an-expired-certificate-for-envoy/889)._
