Managing certificates Adjusting the expiration time of Cloudera Embedded Container Service cluster certificatesThe RKE Kubernetes, Vault, and Cloudera Embedded Container Service webhook certificate expiration times are set to one year by default. To avoid certificate expiration errors, you may want to extend the expiration times.