When recovering from expired certificates, the refreshed csr-controller-ca configmap needs to be propagated to openshift-config-managed namespace to be consumed by CKAO to trust the new client certs.
Refer https://bugzilla.redhat.com/show_bug.cgi?id=1821680#c4, I think we could verify this issue now. tested with payload: 4.5.0-0.nightly-2020-04-12-180647
*** Bug 1818420 has been marked as a duplicate of this bug. ***
*** This bug has been marked as a duplicate of bug 1818420 ***