# Reload controller to pick up new certs?

**URL:** <https://openziti.discourse.group/t/reload-controller-to-pick-up-new-certs/946>\
**Category:** Uncategorized\
**Created:** [December 22, 2022, 9:05pm UTC](https://openziti.discourse.group/t/reload-controller-to-pick-up-new-certs/946 "2022-12-22T21:05:51Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![pixitha](https://avatars.discourse-cdn.com/v4/letter/p/a9a28c/32.png) [@pixitha](https://openziti.discourse.group/u/pixitha)\
**Post date:** [December 22, 2022, 9:05pm UTC](https://openziti.discourse.group/t/reload-controller-to-pick-up-new-certs/946/1 "2022-12-22T21:05:51Z")

</div>

Is there a concept/process for restarting the controller or reloading it to pick up a new cert?

Assuming you’re not using a self signed cert, and you have shorter lifetimes than a year we need to be able to rotate the cert quite often and restarting the service seems rather extreme?

---

<div class="post-metadata">

**Author:** ![andrew.martinez](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/andrew.martinez/32/540_2.png) [@andrew.martinez](https://openziti.discourse.group/u/andrew.martinez)\
**Post date:** [December 22, 2022, 9:40pm UTC](https://openziti.discourse.group/t/reload-controller-to-pick-up-new-certs/946/2 "2022-12-22T21:40:05Z")

</div>

There has been internal work to support such features in a generic capacity in shared libraries, but it hasn’t surfaced in all places. It would only support `file:<path>` configurations in its current form. Hardware-backed storage would need its own engine-backed implementation that has not been investigated. Additionally, mutating `<pem>:<pem-cert/pem-key>` is not currently supported. The goal was mainly aimed at routers and alternative server certificates. There are caveats and sharp edges to what you are asking about. I have a few questions if you don’t mind:

1. Are you rotating the `server_cert`, `cert`, and/or `alt_server_certs` (defined [here](https://openziti.github.io/operations/configuration/conventions#identity))
2. Are you looking to rotate the [edge signing certificate](https://openziti.github.io/operations/configuration/controller#signingcert)?
3. Are you additionally changing the root or intermediate CAs?
4. Are you changing the paths the config points to or simply altering the file contents that the config points to?

---

<div class="post-metadata">

**Author:** ![pixitha](https://avatars.discourse-cdn.com/v4/letter/p/a9a28c/32.png) [@pixitha](https://openziti.discourse.group/u/pixitha)\
**Post date:** [December 23, 2022, 3:38pm UTC](https://openziti.discourse.group/t/reload-controller-to-pick-up-new-certs/946/3 "2022-12-23T15:38:55Z")

</div>

1. Rotating the server\_cert/cert (they are the same in our case).
2. No, we have that with a long lifetime.
3. Nope
4. Nope, just recreating/writing the existing cert/key file.

---

<div class="post-metadata">

**Author:** ![pixitha](https://avatars.discourse-cdn.com/v4/letter/p/a9a28c/32.png) [@pixitha](https://openziti.discourse.group/u/pixitha)\
**Post date:** [February 15, 2023, 9:18pm UTC](https://openziti.discourse.group/t/reload-controller-to-pick-up-new-certs/946/4 "2023-02-15T21:18:50Z")

</div>

Any updates on this?

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [February 15, 2023, 9:21pm UTC](https://openziti.discourse.group/t/reload-controller-to-pick-up-new-certs/946/5 "2023-02-15T21:21:25Z")

</div>

Sorry @pixitha … Holiday season and it’s easy to miss following up… @andrew.martinez is out at least till tomorrow. Thanks for the bump. I’ll try to grab his attention on this one too.

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [February 15, 2023, 9:23pm UTC](https://openziti.discourse.group/t/reload-controller-to-pick-up-new-certs/946/6 "2023-02-15T21:23:12Z")

</div>

FWIW, the process of restarting routers and controller is “very fast” so most likely, humans would never even notice a restart blip. That said, it’d certainly be friendly if the server just recognized the certs change and reloaded 'em.

---

<div class="post-metadata">

**Author:** ![pixitha](https://avatars.discourse-cdn.com/v4/letter/p/a9a28c/32.png) [@pixitha](https://openziti.discourse.group/u/pixitha)\
**Post date:** [February 15, 2023, 9:57pm UTC](https://openziti.discourse.group/t/reload-controller-to-pick-up-new-certs/946/7 "2023-02-15T21:57:55Z")

</div>

No worries, I had forgotten about this issue until the cert expired again. Yeah right now we are just restarting the controller by hand as needed.

---

<div class="post-metadata">

**Author:** ![pixitha](https://avatars.discourse-cdn.com/v4/letter/p/a9a28c/32.png) [@pixitha](https://openziti.discourse.group/u/pixitha)\
**Post date:** [February 28, 2023, 5:32pm UTC](https://openziti.discourse.group/t/reload-controller-to-pick-up-new-certs/946/8 "2023-02-28T17:32:04Z")

</div>

Any updates from @andrew.martinez ?
