https://github.com/osquery/osquery logo
Title
n

nick fury

03/14/2023, 12:34 PM
I need to change the fleet certificate, do you have any idea how can I do it because if i change the certificate all my agent will get disconnected and it will take time to update all the certificated at the agents
l

Lucas Rodriguez

03/14/2023, 2:24 PM
Hi @nick fury! If you are using a custom certificate on the endpoints and you are changing to a completely different certificate, then yes, updating it will require modifying the certificate already deployed in the agents.
n

nick fury

03/14/2023, 2:32 PM
its not completely different, this is a same URL because the Esperion date of my certificate is in couple of months
l

Lucas Rodriguez

03/14/2023, 2:33 PM
OK, but do the certificates share a root/intermediate CA?
n

nick fury

03/14/2023, 2:34 PM
@Lucas Rodriguez are you saying that there is nothing I can do? and my agents will be disconnected for some time?
yes a private CA
l

Lucas Rodriguez

03/14/2023, 4:42 PM
OK, then it's worth testing if your agents really need to have their certificates changed, maybe they'll trust the new certificate because it's signed by the same CA?