Unable to connect to the server: x509: certificate has expired or is not yet valid / certificate signed by unknown authority
kubectl doesn’t trust the API server’s certificate — it expired (kubeadm clusters after 1 year), the CA in kubeconfig is wrong, or a proxy intercepts TLS.
Seen on:
Kubernetes
Meaning
kubeadm-issued certificates last one year unless the cluster is upgraded. Recreated clusters keep the same name but a new CA, so old kubeconfigs fail. Corporate TLS inspection also breaks verification.
Common causes
- kubeadm control-plane certificates expired
- kubeconfig has an old CA (cluster recreated)
- Clock skew on your machine
- TLS-intercepting proxy between you and the API
⚡ Quick fix
- kubeadm certs check-expiration and renew
- Download a fresh kubeconfig
- Exclude the API server from the proxy
Detailed fix by platform
Kubernetes
- bash
sudo kubeadm certs check-expiration sudo kubeadm certs renew all && sudo systemctl restart kubelet sudo cp /etc/kubernetes/admin.conf ~/.kube/config
How to diagnose
- Expiry — openssl s_client -connect api:6443 | openssl x509 -noout -dates
- CA — Does kubeconfig match the cluster?
- Clock — date
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in Kubernetes
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026