Unable to rotate the RSA key pair used for OpenShift Manual Mode with Amazon STS in RHOCP 4
Issue
-
Updating the private key in the cluster's
initial-bounding-signing-keyssecretdoesn't propagate the change to validate newWebIdentity tokensagainst AWS. -
Public signing key is unable to point recreated
OIDC
Environment
- Red Hat OpenShift Container Platform (RHOCP) 4+
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.