Description of problem: Default install of undercloud will break after 1 year, because of how local certificate generation is handled How reproducible: Will happen if an undercloud install is not run for about a year Actual results: undercloud cli command will throw a certificate trust error after a year Expected results: The undercloud server certificate to be trusted by the director Additional info: There is a fix upstream for train for this issue in puppet-tripleo https://review.opendev.org/c/openstack/puppet-tripleo/+/855310 And downstream bug https://bugzilla.redhat.com/show_bug.cgi?id=2104546 But this fix would need to be refactored for any release from wabbly onwards, as the certmonger post-save renewal script was moved from puppet-tripleo to tripleo-ansible in wallaby.