Existing private key in Secret "docker-registry-tls-certificate" has mismatching fields: [spec.keySize]

Viewed 599

I had a problem while installing the docker registry on Kubernetes. Although I have repeatedly created and removed the TLS-certificate, I am notified that your certificate is out of date for this spec:

Events:
  Type     Reason        Age    From          Message
  ----     ------        ----   ----          -------
  Normal   Issuing       2m40s  cert-manager  Existing private key is not up to date for spec: [spec.keySize]
  Warning  DecodeFailed  2m40s  cert-manager  Existing private key in Secret "docker-registry-tls-certificate" does not match requirements on Certificate resource, mismatching fields: [spec.keySize]

Also, when I check our certificates, I see that our TLS certificate is not ready:

[root@kube-master-0 dockerRegistry]# kubectl get certs
NAME                              READY   SECRET                            AGE
docker-registry-tls               True    docker-registry-tls-certificate   6m53s
docker-registry-tls-certificate   False   docker-registry-tls-certificate   7m14s

Our Certificate yaml file:

# 01 Staging Environment over SelfSignedCert witthout a Public DNS
apiVersion: cert-manager.io/v1alpha2
kind: Issuer
metadata:
  name: demo-issuer
spec:
  selfSigned: {}

---
apiVersion: cert-manager.io/v1alpha2
kind: Certificate
metadata:
  name: docker-registry-tls
spec:
  # Secret names are always required.
  secretName: docker-registry-tls-certificate
  duration: 2160h # 90d
  renewBefore: 360h # 15d
  # The use of the common name field has been deprecated since 2000 and is
  # discouraged from being used.
  commonName: registry.example.com
  isCA: false
  keySize: 4096
  keyAlgorithm: rsa
  keyEncoding: pkcs1
  usages:
    - server auth
    - client auth
  # At least one of a DNS Name, URI, or IP address is required.
  dnsNames:
  - registry.example.com
  - example.com
  ipAddresses:
  - 192.168.50.101
  - 192.168.50.102
  # Issuer references are always required.
  issuerRef:
    name: demo-issuer
    # We can reference ClusterIssuers by changing the kind here.
    # The default value is Issuer (i.e. a locally namespaced Issuer)
    kind: Issuer
    # This is optional since cert-manager will default to this value however
    # if you are using an external issuer, change this to that issuer group.
    group: cert-manager.io

What could be the root cause of this problem? How can I fix the problem?

1 Answers

Its due to the docker-registry-tls-certificate already having a TLS certificate/key placed in, which is a different key size to the keySize of the Certificate spec.keySize.

It appears to be a change in behaviour of cert-manager where it would previously overwrite it with a new issued certificate even if the key size was different, but now prevents updating the Secret if the key is of different size.

This might be for example a fake self-signed certificate deployed with docker-registry to get the resources up and running, which a cert-manager Certificate is replacing.

To fix you can replace the docker-registry-tls-certificate Secret's tls.crt/key with a fake one of the same key length as the one your Certificate resource is requesting, or remove it completely if it is not needed.

Related