diff --git a/Standards/scs-0215-v1-robustness-features.md b/Standards/scs-0215-v1-robustness-features.md index 2179997b7..9f76fdfac 100644 --- a/Standards/scs-0215-v1-robustness-features.md +++ b/Standards/scs-0215-v1-robustness-features.md @@ -225,7 +225,7 @@ How this is done is up to the operator. It should be avoided, that certificates expire either on the whole cluster or for single components. To avoid this scenario, certificates SHOULD be rotated regularly; in the case of SCS, we REQUIRE at least a yearly certificate rotation. -To achieve a complete certificate rotation, the parameters `serverTLSBootstrap` and `rotateCertificates` +To achieve a complete certificate rotation, the parameters `serverTLSBootstrap` and `rotateCertificates` MUST be set in the kubelet configuration. The certificates can be rotated by either updating the Kubernetes cluster, which automatically