See below for the Validation Authority bugs fixed in Cryptographic Security Platform 1.4.0.

Integration errors with CA Gateway (ATEAM-18916)

Integration with CA Gateway may fail when the Validation Authority client certificate is not issued by a root CA.

Running shims are not moved after a node dies (PKIPM-1090)

When a node dies, Entrust Validation Authority does not move the pod running shims to a live node. Therefore, these shims prevent updates to the database.

Workaround: Wait for the dead node to return, or kill the pod as follows. 

  1. List the pods.

    sudo kubectl get pods -n eva -o wide
  2. Kill the dead pod. For example:

    sudo kubectl -n eva delete pod --force eva-cagwshim-n-0