x509 (kubectl) ☸️ Kubernetes

Unable to connect to the server: x509: certificate has expired or is not yet valid / certificate signed by unknown authority

kubectl doesn’t trust the API server’s certificate — it expired (kubeadm clusters after 1 year), the CA in kubeconfig is wrong, or a proxy intercepts TLS.

Seen on: Kubernetes

Meaning

kubeadm-issued certificates last one year unless the cluster is upgraded. Recreated clusters keep the same name but a new CA, so old kubeconfigs fail. Corporate TLS inspection also breaks verification.

Common causes

  • kubeadm control-plane certificates expired
  • kubeconfig has an old CA (cluster recreated)
  • Clock skew on your machine
  • TLS-intercepting proxy between you and the API

⚡ Quick fix

  1. kubeadm certs check-expiration and renew
  2. Download a fresh kubeconfig
  3. Exclude the API server from the proxy

Detailed fix by platform

Kubernetes

  1. bash
    sudo kubeadm certs check-expiration
    sudo kubeadm certs renew all && sudo systemctl restart kubelet
    sudo cp /etc/kubernetes/admin.conf ~/.kube/config

How to diagnose

  1. Expiry — openssl s_client -connect api:6443 | openssl x509 -noout -dates
  2. CA — Does kubeconfig match the cluster?
  3. Clock — date

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.