# \#certificates

**URL:** https://linkerd.buoyant.io/tag/certificates/15.md

[Latest](https://linkerd.buoyant.io/latest.md) · [Categories](https://linkerd.buoyant.io/categories.md) · [Tags](https://linkerd.buoyant.io/tags.md)

---

## [linkerd-Identity-Issuer not refreshing certificates as expected](https://linkerd.buoyant.io/t/linkerd-identity-issuer-not-refreshing-certificates-as-expected/811)

<div class="topic-metadata">

**Author:** [@Shubham](https://linkerd.buoyant.io/u/Shubham)\
**Replies:** 5\
**Last updated:** [January 8, 2026, 4:13pm UTC](https://linkerd.buoyant.io/t/linkerd-identity-issuer-not-refreshing-certificates-as-expected/811 "2026-01-08T16:13:46Z")

</div>

Recently we’ve started facing issue with outbound calls for some pods when trying to connect with services within same cluster. Can see following logs in proxy \[9515905.481616s\] WARN ThreadId(01) outbound:proxy{addr=1…

---

## [Can external devices like F5 BIG-IP use MTLs certificates to talk to mTLS meshed pods?](https://linkerd.buoyant.io/t/can-external-devices-like-f5-big-ip-use-mtls-certificates-to-talk-to-mtls-meshed-pods/826)

<div class="topic-metadata">

**Author:** [@Nikolayy1](https://linkerd.buoyant.io/u/Nikolayy1)\
**Replies:** 3\
**Last updated:** [November 20, 2025, 3:40pm UTC](https://linkerd.buoyant.io/t/can-external-devices-like-f5-big-ip-use-mtls-certificates-to-talk-to-mtls-meshed-pods/826 "2025-11-20T15:40:18Z")

</div>

Hello Everyone, My question is Can external devices like F5 BIG-IP use MTLs certificates to talk to mTLS meshed pods? The idea is that F5 BIG-IP uses CIS F5Networks/k8s-bigip-ctlr: Repository for F5 Container Ingress S…

---

## [Linkerd does not start when using Cert Manager and Trust manager to rotate the MTLS certs](https://linkerd.buoyant.io/t/linkerd-does-not-start-when-using-cert-manager-and-trust-manager-to-rotate-the-mtls-certs/825)

<div class="topic-metadata">

**Author:** [@Nikolayy1](https://linkerd.buoyant.io/u/Nikolayy1)\
**Replies:** 0\
**Last updated:** [November 14, 2025, 9:38am UTC](https://linkerd.buoyant.io/t/linkerd-does-not-start-when-using-cert-manager-and-trust-manager-to-rotate-the-mtls-certs/825 "2025-11-14T09:38:22Z")

</div>

Followed article Automatically Rotating Control Plane TLS Credentials | Linkerd but linkerd did not start because of config error. kubectl get pods -A -o wide linkerd linkerd-destination-768cc5bd8c-dxhs5 …

---

## [Linkerd check failed for linkerd-webhooks-and-apisvc-tls. There is no linkerd-proxy injected in our EKS cluster pods](https://linkerd.buoyant.io/t/linkerd-check-failed-for-linkerd-webhooks-and-apisvc-tls-there-is-no-linkerd-proxy-injected-in-our-eks-cluster-pods/806)

<div class="topic-metadata">

**Author:** [@jing.tyagi](https://linkerd.buoyant.io/u/jing.tyagi)\
**Replies:** 1\
**Last updated:** [August 29, 2025, 11:15am UTC](https://linkerd.buoyant.io/t/linkerd-check-failed-for-linkerd-webhooks-and-apisvc-tls-there-is-no-linkerd-proxy-injected-in-our-eks-cluster-pods/806 "2025-08-29T11:15:03Z")

</div>

linkerd-webhooks-and-apisvc-tls × proxy-injector webhook has valid cert anchors not within their validity period: \* 147892185609361118105547867649820840928 linkerd-proxy-injector.linkerd.svc not valid anymore. Expired …

---

## [Linkerd Certificate Management with AWS Private CA Issuer](https://linkerd.buoyant.io/t/linkerd-certificate-management-with-aws-private-ca-issuer/796)

<div class="topic-metadata">

**Author:** [@joebowbeer](https://linkerd.buoyant.io/u/joebowbeer)\
**Replies:** 2\
**Last updated:** [August 5, 2025, 3:04pm UTC](https://linkerd.buoyant.io/t/linkerd-certificate-management-with-aws-private-ca-issuer/796 "2025-08-05T15:04:35Z")

</div>

Related to an earlier blog post and question: Workshop Recap: Linkerd Certificate Management with Vault | Linkerd Security and operational considerations when setting intermediate CA cert expiries (cert-manager) I’m l…

---

## [Security and operational considerations when setting intermediate CA cert expiries (cert-manager)](https://linkerd.buoyant.io/t/security-and-operational-considerations-when-setting-intermediate-ca-cert-expiries-cert-manager/280)

<div class="topic-metadata">

**Author:** [@ltamm](https://linkerd.buoyant.io/u/ltamm)\
**Replies:** 4\
**Last updated:** [July 29, 2025, 8:08pm UTC](https://linkerd.buoyant.io/t/security-and-operational-considerations-when-setting-intermediate-ca-cert-expiries-cert-manager/280 "2025-07-29T20:08:58Z")

</div>

Hello! I’m currently evaluating the use of linkerd in our EKS cluster. I stepped through a replay of your excellent workshop “Linkerd Certificate Management Deep Dive” and think I have a handle on our cert management str…

---

## [Trouble with trusted anchors. I don't know where to look](https://linkerd.buoyant.io/t/trouble-with-trusted-anchors-i-dont-know-where-to-look/783)

<div class="topic-metadata">

**Author:** [@mmclane](https://linkerd.buoyant.io/u/mmclane)\
**Replies:** 3\
**Last updated:** [July 14, 2025, 3:47pm UTC](https://linkerd.buoyant.io/t/trouble-with-trusted-anchors-i-dont-know-where-to-look/783 "2025-07-14T15:47:13Z")

</div>

We have once again been having issues with LinkerD. Seems this happens every couple years. This time we saw that our pods were failing to start. This included the linkerd pods themselves. We saw this in both our dev …

---

## [Linkerd Cert Monitoring](https://linkerd.buoyant.io/t/linkerd-cert-monitoring/775)

<div class="topic-metadata">

**Author:** [@go4brendon](https://linkerd.buoyant.io/u/go4brendon)\
**Replies:** 4\
**Last updated:** [June 18, 2025, 11:38am UTC](https://linkerd.buoyant.io/t/linkerd-cert-monitoring/775 "2025-06-18T11:38:57Z")

</div>

Hi I recently joined a company who where using linkerd in production. Long story short and due to an issue with linkerd certs werent being renewed by cert-manager which caused a bunch of deployments to fall over after be…

---

## [Having https end to end](https://linkerd.buoyant.io/t/having-https-end-to-end/414)

<div class="topic-metadata">

**Author:** [@Msaustral](https://linkerd.buoyant.io/u/Msaustral)\
**Replies:** 1\
**Last updated:** [January 2, 2025, 1:03am UTC](https://linkerd.buoyant.io/t/having-https-end-to-end/414 "2025-01-02T01:03:06Z")

</div>

Hi we have and app that has horizontal scaling by memory consumption, we want to change the scaling by traffic to have a better control over the scaling. Our app is a nginx with http2 and ssl (server side cloudflare) im…

---

## [Linkerd check --proxy](https://linkerd.buoyant.io/t/linkerd-check-proxy/664)

<div class="topic-metadata">

**Author:** [@dverzolla](https://linkerd.buoyant.io/u/dverzolla)\
**Replies:** 3\
**Last updated:** [December 31, 2024, 12:44am UTC](https://linkerd.buoyant.io/t/linkerd-check-proxy/664 "2024-12-31T00:44:42Z")

</div>

Hi, The command linkerd check --proxy say: × trust anchors are within their validity period Invalid anchors: \* 89759643423159114364408881931985711234 root.linkerd.cluster.local not valid anymore. Expired on 2024-1…

---

## [Cert is not issued by the trust anchor error after a couple days](https://linkerd.buoyant.io/t/cert-is-not-issued-by-the-trust-anchor-error-after-a-couple-days/638)

<div class="topic-metadata">

**Author:** [@mkeller](https://linkerd.buoyant.io/u/mkeller)\
**Replies:** 1\
**Last updated:** [November 25, 2024, 3:03pm UTC](https://linkerd.buoyant.io/t/cert-is-not-issued-by-the-trust-anchor-error-after-a-couple-days/638 "2024-11-25T15:03:50Z")

</div>

All - I had so many issues trying to get things working with cert-manager that I resorted to just passing the cert values to linkerd via helm install. Since I’m currently trying to let linkerd manage all the certificates…

---

## [Using linkerd for multi cluster use with firewall](https://linkerd.buoyant.io/t/using-linkerd-for-multi-cluster-use-with-firewall/547)

<div class="topic-metadata">

**Author:** [@kevfoerster](https://linkerd.buoyant.io/u/kevfoerster)\
**Replies:** 2\
**Last updated:** [August 9, 2024, 3:29pm UTC](https://linkerd.buoyant.io/t/using-linkerd-for-multi-cluster-use-with-firewall/547 "2024-08-09T15:29:01Z")

</div>

In our setup, there are two separate kubernetes clusters in virtual private clouds, High and Low. These clusters run the same services, but with different data. No connections can be established from Low to High. All tra…

---

## [Linkerd-tap is not working after 'automatically Rotating Webhook TLS Credentials'](https://linkerd.buoyant.io/t/linkerd-tap-is-not-working-after-automatically-rotating-webhook-tls-credentials/485)

<div class="topic-metadata">

**Author:** [@Hanife](https://linkerd.buoyant.io/u/Hanife)\
**Replies:** 1\
**Last updated:** [June 13, 2024, 1:37pm UTC](https://linkerd.buoyant.io/t/linkerd-tap-is-not-working-after-automatically-rotating-webhook-tls-credentials/485 "2024-06-13T13:37:32Z")

</div>

Hi, we’re currently using Helm to install Linkerd, linkerd-viz and cert-manager to manage the certificates. I configured linkerd-viz for automatic certificate renewal. The steps were followed as in this task page, but th…

---

## [Install linkerd identity certificates with helm](https://linkerd.buoyant.io/t/install-linkerd-identity-certificates-with-helm/462)

<div class="topic-metadata">

**Author:** [@yaronkalatian](https://linkerd.buoyant.io/u/yaronkalatian)\
**Replies:** 3\
**Last updated:** [May 16, 2024, 7:20pm UTC](https://linkerd.buoyant.io/t/install-linkerd-identity-certificates-with-helm/462 "2024-05-16T19:20:15Z")

</div>

Hi , we use flux for helm charts . I want to deploy the linkerd-control-plane I’m using linkerd2-edge for the linkerd-control-plane it written: certificates must live in a ConfigMap resource named linkerd-identity-t…

---

## [Installed tap not working Linkerd 2.14](https://linkerd.buoyant.io/t/installed-tap-not-working-linkerd-2-14/445)

<div class="topic-metadata">

**Author:** [@drisbee](https://linkerd.buoyant.io/u/drisbee)\
**Replies:** 2\
**Last updated:** [May 7, 2024, 12:16pm UTC](https://linkerd.buoyant.io/t/installed-tap-not-working-linkerd-2-14/445 "2024-05-07T12:16:02Z")

</div>

Hi everyone, After installing linkerd-viz and using the internal prometheus I can see the golden metrics in the dashboard. The issue we are now experiencing is that we can’t use tap. In the logging of the tap pod I see…

---

## [Ssl communication between kubernetes services](https://linkerd.buoyant.io/t/ssl-communication-between-kubernetes-services/452)

<div class="topic-metadata">

**Author:** [@jonathan.hernandez](https://linkerd.buoyant.io/u/jonathan.hernandez)\
**Replies:** 2\
**Last updated:** [April 22, 2024, 2:50pm UTC](https://linkerd.buoyant.io/t/ssl-communication-between-kubernetes-services/452 "2024-04-22T14:50:50Z")

</div>

Hello, after asissting Kubecon2024 I started som PoC with linkerd. I’ll explain my use case quickly. I have one namespace. Users have a kiosk application inside this environment. That kiosk has a browser (firefox), so t…

---

## [Tls: failed to verify certificate: x](https://linkerd.buoyant.io/t/tls-failed-to-verify-certificate-x/446)

<div class="topic-metadata">

**Author:** [@mclanem](https://linkerd.buoyant.io/u/mclanem)\
**Replies:** 3\
**Last updated:** [April 18, 2024, 2:32pm UTC](https://linkerd.buoyant.io/t/tls-failed-to-verify-certificate-x/446 "2024-04-18T14:32:07Z")

</div>

I just got LinkerD installed on our Dev cluster. It looks like everything is setup and working. I was able to add a few things to the mesh. I don’t see any errors in the linkerd-proxy container. But when I look at th…

---

## [Issues with step command](https://linkerd.buoyant.io/t/issues-with-step-command/444)

<div class="topic-metadata">

**Author:** [@mclanem](https://linkerd.buoyant.io/u/mclanem)\
**Replies:** 1\
**Last updated:** [April 16, 2024, 2:32pm UTC](https://linkerd.buoyant.io/t/issues-with-step-command/444 "2024-04-16T14:32:46Z")

</div>

Morning everyone. I am trying to follow these instructions: Automatically Rotating Webhook TLS Credentials | Linkerd I am at the part were you use “step” to create signing key pairs and save them as secrets. I install…

---

## [ERROR: failed to verify issuer credentials for 'identity.linkerd.cluster.local' with trust anchors: x509: certificate has expired or is not yet valid](https://linkerd.buoyant.io/t/error-failed-to-verify-issuer-credentials-for-identity-linkerd-cluster-local-with-trust-anchors-x509-certificate-has-expired-or-is-not-yet-valid/348)

<div class="topic-metadata">

**Author:** [@Bhavya](https://linkerd.buoyant.io/u/Bhavya)\
**Replies:** 4\
**Last updated:** [January 22, 2024, 6:58am UTC](https://linkerd.buoyant.io/t/error-failed-to-verify-issuer-credentials-for-identity-linkerd-cluster-local-with-trust-anchors-x509-certificate-has-expired-or-is-not-yet-valid/348 "2024-01-22T06:58:59Z")

</div>

We have deployed Linkerd using the helm charts. For certificates, we are using cert-manager for auto-renewal of certificates. The certificate itself would be valid for 48h but we have set the renewal for 24h. Randomly, …

---

## [Automatically Upgrading Linkerd](https://linkerd.buoyant.io/t/automatically-upgrading-linkerd/294)

<div class="topic-metadata">

**Author:** [@sabrinaGPS](https://linkerd.buoyant.io/u/sabrinaGPS)\
**Replies:** 6\
**Last updated:** [October 29, 2023, 6:12pm UTC](https://linkerd.buoyant.io/t/automatically-upgrading-linkerd/294 "2023-10-29T18:12:48Z")

</div>

Instead of going through the process of replacing expired certificates that’s documented, is it true that if you just upgrade Linkerd it will update all the certificates as well? Could you write a script to automate the …

---

## [Http: TLS handshake error from tap pod](https://linkerd.buoyant.io/t/http-tls-handshake-error-from-tap-pod/303)

<div class="topic-metadata">

**Author:** [@djaramil](https://linkerd.buoyant.io/u/djaramil)\
**Replies:** 1\
**Last updated:** [October 28, 2023, 3:00pm UTC](https://linkerd.buoyant.io/t/http-tls-handshake-error-from-tap-pod/303 "2023-10-28T15:00:18Z")

</div>

We are seeing tls handshake failure on the tap pod container and want to know if this is a soft or hard error. time=“2023-10-27T17:43:00Z” level=info msg=“caches synced” time=“2023-10-27T17:43:00Z” level=info msg=“star…

---

## [Create a script that can automatically update the needed certifications for Linkerd once they expire](https://linkerd.buoyant.io/t/create-a-script-that-can-automatically-update-the-needed-certifications-for-linkerd-once-they-expire/283)

<div class="topic-metadata">

**Author:** [@sabrinaGPS](https://linkerd.buoyant.io/u/sabrinaGPS)\
**Replies:** 6\
**Last updated:** [October 20, 2023, 2:48pm UTC](https://linkerd.buoyant.io/t/create-a-script-that-can-automatically-update-the-needed-certifications-for-linkerd-once-they-expire/283 "2023-10-20T14:48:49Z")

</div>

If we aren’t using the Enterprise version of Linkerd, is there a way we could create a script to automate the renewal of the certifications that are needed to keep Linkerd running? Or how could we extend the life of a c…

---

## [Linkerd disable mtls in the runtime](https://linkerd.buoyant.io/t/linkerd-disable-mtls-in-the-runtime/233)

<div class="topic-metadata">

**Author:** [@zsk](https://linkerd.buoyant.io/u/zsk)\
**Replies:** 1\
**Last updated:** [September 27, 2023, 5:26pm UTC](https://linkerd.buoyant.io/t/linkerd-disable-mtls-in-the-runtime/233 "2023-09-27T17:26:41Z")

</div>

I’ve found how to do it with --disable-identity flag, but this will require a restart of the pod. And I just wonder, is there a way to disable mtls at the runtime without pod restart? This will be helpful if something h…

---

## [\[Cert-Manager\] Webhook Certificates renewal Failure](https://linkerd.buoyant.io/t/cert-manager-webhook-certificates-renewal-failure/223)

<div class="topic-metadata">

**Author:** [@pt](https://linkerd.buoyant.io/u/pt)\
**Replies:** 4\
**Last updated:** [August 16, 2023, 2:13pm UTC](https://linkerd.buoyant.io/t/cert-manager-webhook-certificates-renewal-failure/223 "2023-08-16T14:13:23Z")

</div>

When performing a linkerd check --proxy we’re experiencing an error cert is not issued by the trust anchor: x509: certificate signed by unknown authority which doesn’t make much sense to me. To my understanding, webhook …

---

## [Digital Ocean Linkerd app](https://linkerd.buoyant.io/t/digital-ocean-linkerd-app/191)

<div class="topic-metadata">

**Author:** [@dgolubets](https://linkerd.buoyant.io/u/dgolubets)\
**Replies:** 1\
**Last updated:** [July 27, 2023, 5:44pm UTC](https://linkerd.buoyant.io/t/digital-ocean-linkerd-app/191 "2023-07-27T17:44:09Z")

</div>

Hi, Is the market place app in Digital Ocean a preferred way of installing it there? Does it have any special handling of certificates updates by a chance? I also wonder how can it be updated from 2.12 to 2.13?
