$ sudo kubeadm certs check-expiration
[sudo] password for deptno:
[check-expiration] Reading configuration from the cluster...
[check-expiration] FYI: You can look at this config file with 'kubectl -n kube-system get cm kubeadm-config -o yaml'
CERTIFICATE EXPIRES RESIDUAL TIME CERTIFICATE AUTHORITY EXTERNALLY MANAGED
admin.conf Jan 13, 2024 16:03 UTC 331d ca no
apiserver Feb 02, 2024 13:04 UTC 351d ca no
apiserver-etcd-client Jan 13, 2024 16:03 UTC 331d etcd-ca no
apiserver-kubelet-client Jan 13, 2024 16:03 UTC 331d ca no
controller-manager.conf Jan 13, 2024 16:03 UTC 331d ca no
etcd-healthcheck-client Jan 13, 2024 16:03 UTC 331d etcd-ca no
etcd-peer Jan 13, 2024 16:03 UTC 331d etcd-ca no
etcd-server Jan 13, 2024 16:03 UTC 331d etcd-ca no
front-proxy-client Jan 13, 2024 16:03 UTC 331d front-proxy-ca no
scheduler.conf Jan 13, 2024 16:03 UTC 331d ca no
CERTIFICATE AUTHORITY EXPIRES RESIDUAL TIME EXTERNALLY MANAGED
ca Jan 10, 2033 16:03 UTC 9y no
etcd-ca Jan 10, 2033 16:03 UTC 9y no
front-proxy-ca Jan 10, 2033 16:03 UTC 9y no
zz
[check-expiration] Reading configuration from the cluster...
[check-expiration] FYI: You can look at this config file with 'kubectl -n kube-system get cm kubeadm-config -o yaml'
CERTIFICATE EXPIRES RESIDUAL TIME CERTIFICATE AUTHORITY EXTERNALLY MANAGED
admin.conf Jan 13, 2024 16:03 UTC 331d ca no
apiserver Feb 02, 2024 13:04 UTC 351d ca no
apiserver-etcd-client Jan 13, 2024 16:03 UTC 331d etcd-ca no
apiserver-kubelet-client Jan 13, 2024 16:03 UTC 331d ca no
controller-manager.conf Jan 13, 2024 16:03 UTC 331d ca no
etcd-healthcheck-client Jan 13, 2024 16:03 UTC 331d etcd-ca no
etcd-peer Jan 13, 2024 16:03 UTC 331d etcd-ca no
etcd-server Jan 13, 2024 16:03 UTC 331d etcd-ca no
front-proxy-client Jan 13, 2024 16:03 UTC 331d front-proxy-ca no
scheduler.conf Jan 13, 2024 16:03 UTC 331d ca no
CERTIFICATE AUTHORITY EXPIRES RESIDUAL TIME EXTERNALLY MANAGED
ca Jan 10, 2033 16:03 UTC 9y no
etcd-ca Jan 10, 2033 16:03 UTC 9y no
front-proxy-ca Jan 10, 2033 16:03 UTC 9y no