<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/rotating-expiring-x-509-certificates-in-percona-server-for-mongodb-with-minimal-service-interruption-qgw1atksp" -->

---
title: Rotating Expiring X.509 Certificates in Percona Server...
description: Expired TLS certificates can block new client connections and, when X.509 authentication is used, prevent replica set or sharded cluster members from...
canonical: https://daily.dev/posts/rotating-expiring-x-509-certificates-in-percona-server-for-mongodb-with-minimal-service-interruption-qgw1atksp
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Rotating Expiring X.509 Certificates in Percona Server for MongoDB with Minimal Service Interruption | daily.dev
og:description: Expired TLS certificates can block new client connections and, when X.509 authentication is used, prevent replica set or sharded cluster members from...
og:url: https://daily.dev/posts/rotating-expiring-x-509-certificates-in-percona-server-for-mongodb-with-minimal-service-interruption-qgw1atksp
og:image: https://api.daily.dev/og/posts/QGw1ATKSP.png
og:image:alt: Rotating Expiring X.509 Certificates in Percona Server for MongoDB with Minimal Service Interruption
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Rotating Expiring X.509 Certificates in Percona Server for MongoDB with Minimal Service Interruption

**[Percona Blog](https://daily.dev/sources/percona)** · 3 min read · 0 upvotes · 0 comments

## Summary

Expired TLS certificates can block new client connections and, when X.509 authentication is used, prevent replica set or sharded cluster members from authenticating with each other in Percona Server for MongoDB. The post explains how to perform a same-CA renewal using the rotateCertificates command to hot-reload TLS material without restarting mongod or mongos, covering certificateKeyFile and clusterFile options, validation steps after rotation, and warnings against using this procedure when the issuing CA, subject DN, or cluster-membership attributes change.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.percona.com/blog/rotating-expiring-x-509-certificates-in-percona-server-for-mongodb-with-minimal-service-interruption>

## Questions this post answers

### How do I renew expiring TLS certificates on a MongoDB replica set without restarting mongod?

Use the rotateCertificates command for a same-CA renewal, where replacement certificates are issued by the existing trusted CA and X.509 cluster-membership attributes don't change. This reloads the certificateKeyFile and clusterFile TLS material for new connections without restarting mongod or mongos, terminating existing sessions, or triggering a replica-set election. Validate with a fresh TLS connection and check logs for the rotation confirmation.

_Teams tracking zero-downtime certificate rotation steps for MongoDB clusters can follow ongoing guidance on daily.dev._

### What happens if a MongoDB certificate rotation fails partway through?

Incorrect or invalid certificate files cause the rotation to fail, but they do not invalidate the existing TLS configuration or cause other side effects. The rotateCertificates command reloads all configured TLS inputs, such as certificateKeyFile, clusterFile, CAFile, and CRL, as a single set, so a missing or invalid input causes the entire reload attempt to fail safely.

_Ops teams weighing certificate rotation risk before a production maintenance window can find this on daily.dev._

### When can't I use rotateCertificates to renew a MongoDB X.509 certificate without downtime?

The hot-reload rotateCertificates procedure should not be used when replacing the issuing CA, changing a certificate's subject DN, or changing cluster-membership attributes for X.509 internal authentication. Those changes require a different, more involved procedure than a simple same-CA certificate renewal, since they alter the trust relationships between cluster members rather than just refreshing expiring material.

_Anyone planning a MongoDB CA or cluster-membership change can track the right procedure to avoid outages via daily.dev._

## Similar posts on daily.dev

- [Enabling TLS in PXC without Downtime](https://daily.dev/posts/enabling-tls-in-pxc-without-downtime-rfvq6qcfq) · Planet MySQL · 0 upvotes · 0 comments
- [Enforcing TLS and managing certificate rotation for RDS and Amazon Aurora PostgreSQL](https://daily.dev/posts/enforcing-tls-and-managing-certificate-rotation-for-rds-and-amazon-aurora-postgresql-mruniy8os) · AWS Database Blog · 0 upvotes · 0 comments
- [Mutual TLS in SingleStore](https://daily.dev/posts/mutual-tls-in-singlestore-07wanpuno) · SingleStore · 0 upvotes · 0 comments
- [Multi-Cluster databases on Kubernetes: Architecture and deployment](https://daily.dev/posts/multi-cluster-databases-on-kubernetes-architecture-and-deployment-yats0aq1j) · CNCF · 1 upvotes · 0 comments

---

Tags: [#database](https://daily.dev/tags/database), [#mongodb](https://daily.dev/tags/mongodb)

[View this post on daily.dev](https://daily.dev/posts/rotating-expiring-x-509-certificates-in-percona-server-for-mongodb-with-minimal-service-interruption-qgw1atksp)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Rotating Expiring X.509 Certificates in Percona Server for MongoDB with Minimal Service Interruption","url":"https://daily.dev/posts/rotating-expiring-x-509-certificates-in-percona-server-for-mongodb-with-minimal-service-interruption-qgw1atksp","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/rotating-expiring-x-509-certificates-in-percona-server-for-mongodb-with-minimal-service-interruption-qgw1atksp"},"datePublished":"2026-08-31T12:17:30.023Z","dateModified":"2026-09-14T09:14:51.753Z","description":"Expired TLS certificates can block new client connections and, when X.509 authentication is used, prevent replica set or sharded cluster members from...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/3cb30bc7f150cbb040c6a3e7859f30c0?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/3cb30bc7f150cbb040c6a3e7859f30c0?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Percona Blog","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Percona Blog","logo":"https://media.daily.dev/image/upload/s--Lb3XkBh3--/f_auto,q_auto/v1780213412/logos/percona?_a=BAMAMiWQ0","url":"https://daily.dev/sources/percona"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/rotating-expiring-x-509-certificates-in-percona-server-for-mongodb-with-minimal-service-interruption-qgw1atksp","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"database,mongodb","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Percona Blog","item":"https://daily.dev/sources/percona"},{"@type":"ListItem","position":3,"name":"Rotating Expiring X.509 Certificates in Percona Server for MongoDB with Minimal Service Interruption"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/rotating-expiring-x-509-certificates-in-percona-server-for-mongodb-with-minimal-service-interruption-qgw1atksp#faq","mainEntity":[{"@type":"Question","name":"How do I renew expiring TLS certificates on a MongoDB replica set without restarting mongod?","acceptedAnswer":{"@type":"Answer","text":"Use the rotateCertificates command for a same-CA renewal, where replacement certificates are issued by the existing trusted CA and X.509 cluster-membership attributes don't change. This reloads the certificateKeyFile and clusterFile TLS material for new connections without restarting mongod or mongos, terminating existing sessions, or triggering a replica-set election. Validate with a fresh TLS connection and check logs for the rotation confirmation. Teams tracking zero-downtime certificate rotation steps for MongoDB clusters can follow ongoing guidance on daily.dev."}},{"@type":"Question","name":"What happens if a MongoDB certificate rotation fails partway through?","acceptedAnswer":{"@type":"Answer","text":"Incorrect or invalid certificate files cause the rotation to fail, but they do not invalidate the existing TLS configuration or cause other side effects. The rotateCertificates command reloads all configured TLS inputs, such as certificateKeyFile, clusterFile, CAFile, and CRL, as a single set, so a missing or invalid input causes the entire reload attempt to fail safely. Ops teams weighing certificate rotation risk before a production maintenance window can find this on daily.dev."}},{"@type":"Question","name":"When can't I use rotateCertificates to renew a MongoDB X.509 certificate without downtime?","acceptedAnswer":{"@type":"Answer","text":"The hot-reload rotateCertificates procedure should not be used when replacing the issuing CA, changing a certificate's subject DN, or changing cluster-membership attributes for X.509 internal authentication. Those changes require a different, more involved procedure than a simple same-CA certificate renewal, since they alter the trust relationships between cluster members rather than just refreshing expiring material. Anyone planning a MongoDB CA or cluster-membership change can track the right procedure to avoid outages via daily.dev."}}]}
```

