Renew and change SSL/TLS certificates
If your current SSL/TLS certificates have expired or will expire soon, you can either renew or replace the SSL/TLS certificates used by Ansible Automation Platform.
You must renew the SSL/TLS certificates if you need to regenerate them with new information such as new hosts.
You must replace the SSL/TLS certificates if you want to use certificates signed by an internal certificate authority.
- Container-based installations
You can change the TLS certificates and keys for your container-based Ansible Automation Platform installation. This process involves a preparation step, either providing new custom certificates or deleting or moving the old certificates, followed by running the installation program. - Operator-based installations
You can change the TLS certificates and keys for your operator-based Ansible Automation Platform installation. - RPM-based installations
To renew or change SSL/TLS certificates for RPM-based installations, you can edit the inventory file and run the installation program. The installation program verifies that all Ansible Automation Platform components are working. - Configure a CA file
Use this example to customize the default definition file to include a CA certificate to theadditional-build-filessection, move the file to the appropriate directory and, run the command to update the dynamic configuration of CA certificates to allow the system to trust this certificate.