mirror of https://github.com/docker/docs.git
Merge pull request #16596 from neersighted/swarm_ca_rotate_mke
swarm: call out CA rotation as potentially dangerous with MKE
This commit is contained in:
commit
ff1483fb7a
|
@ -60,6 +60,13 @@ reference for details.
|
||||||
|
|
||||||
## Rotating the CA certificate
|
## Rotating the CA certificate
|
||||||
|
|
||||||
|
> **Note**
|
||||||
|
>
|
||||||
|
> Mirantis Kubernetes Engine (MKE), formerly known as Docker UCP, provides an external
|
||||||
|
> certificate manager service for the swarm. If you run swarm on MKE, you shouldn't
|
||||||
|
> rotate the CA certificates manually. Instead, contact Mirantis support if you need
|
||||||
|
> to rotate a certificate.
|
||||||
|
|
||||||
In the event that a cluster CA key or a manager node is compromised, you can
|
In the event that a cluster CA key or a manager node is compromised, you can
|
||||||
rotate the swarm root CA so that none of the nodes trust certificates
|
rotate the swarm root CA so that none of the nodes trust certificates
|
||||||
signed by the old root CA anymore.
|
signed by the old root CA anymore.
|
||||||
|
|
Loading…
Reference in New Issue