--- apiVersion: certificates.k8s.io/v1 kind: CertificateSigningRequest metadata: creationTimestamp: "2026-03-19T11:53:12Z" generateName: system:openshift:openshift-authenticator- labels: authentication.openshift.io/csr: openshift-authenticator managedFields: - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:metadata: f:generateName: {} f:labels: .: {} f:authentication.openshift.io/csr: {} manager: authentication-operator operation: Update time: "2026-03-19T11:53:12Z" - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:status: f:conditions: .: {} k:{"type":"Approved"}: .: {} f:lastTransitionTime: {} f:lastUpdateTime: {} f:message: {} f:reason: {} f:status: {} f:type: {} manager: authentication-operator operation: Update subresource: approval time: "2026-03-19T11:53:12Z" - apiVersion: certificates.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:status: f:certificate: {} manager: kube-controller-manager operation: Update subresource: status time: "2026-03-19T11:53:12Z" name: system:openshift:openshift-authenticator-kxdbx resourceVersion: "4231" uid: bf0cc2ae-7fad-44ca-97d5-b51d7c162030 spec: extra: authentication.kubernetes.io/credential-id: - JTI=3c561882-8131-4ce1-aecf-498eae3bba33 authentication.kubernetes.io/node-name: - master-0 authentication.kubernetes.io/node-uid: - 41b47749-a7d7-429f-9c0a-3925a76dc079 authentication.kubernetes.io/pod-name: - authentication-operator-5885bfd7f4-gqd94 authentication.kubernetes.io/pod-uid: - 732989c5-1b89-46f0-9917-b68613f7f005 groups: - system:serviceaccounts - system:serviceaccounts:openshift-authentication-operator - system:authenticated request: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURSBSRVFVRVNULS0tLS0KTUlJQkRUQ0J0QUlCQURCU01WQXdUZ1lEVlFRREUwZHplWE4wWlcwNmMyVnlkbWxqWldGalkyOTFiblE2YjNCbApibk5vYVdaMExXOWhkWFJvTFdGd2FYTmxjblpsY2pwdmNHVnVjMmhwWm5RdFlYVjBhR1Z1ZEdsallYUnZjakJaCk1CTUdCeXFHU000OUFnRUdDQ3FHU000OUF3RUhBMElBQkprQXJiZXBvK244ZndFVDJqK1ZjSU9YdTdpbDZLTUsKMUpOU1U0RnJzMzZtb3RZUC93eC94UndwbUlFb2FabHF1b3pLdVpSOEYvbkI0dnRsU0xud0Q2S2dBREFLQmdncQpoa2pPUFFRREFnTklBREJGQWlFQWhRUmRMRzNUTnk0Nk1vSWVyWndpSG1DdEs1T3AzaWJHZGdTbE41cWpkNHNDCklBT0RCbkc2WEFMaVhDa2pGOENCVFNFSHYyNm1JL0NUcXFySmVDWk5SRExyCi0tLS0tRU5EIENFUlRJRklDQVRFIFJFUVVFU1QtLS0tLQo= signerName: kubernetes.io/kube-apiserver-client uid: 8525a204-7c08-43d8-a37f-d83b912d2526 usages: - digital signature - key encipherment - client auth username: system:serviceaccount:openshift-authentication-operator:authentication-operator status: certificate: LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUNsRENDQVh5Z0F3SUJBZ0lRQW9sS1QvRmNOOGFxVTM0dFVxai9sakFOQmdrcWhraUc5dzBCQVFzRkFEQXQKTVJJd0VBWURWUVFMRXdsdmNHVnVjMmhwWm5ReEZ6QVZCZ05WQkFNVERtdDFZbVZzWlhRdGMybG5ibVZ5TUI0WApEVEkyTURNeE9URXhORGd4TWxvWERUSTJNRE15TURFeE5ETXdNMW93VWpGUU1FNEdBMVVFQXhOSGMzbHpkR1Z0Ck9uTmxjblpwWTJWaFkyTnZkVzUwT205d1pXNXphR2xtZEMxdllYVjBhQzFoY0dselpYSjJaWEk2YjNCbGJuTm8KYVdaMExXRjFkR2hsYm5ScFkyRjBiM0l3V1RBVEJnY3Foa2pPUFFJQkJnZ3Foa2pPUFFNQkJ3TkNBQVNaQUsyMwpxYVBwL0g4QkU5by9sWENEbDd1NHBlaWpDdFNUVWxPQmE3TitwcUxXRC84TWY4VWNLWmlCS0dtWmFycU15cm1VCmZCZjV3ZUw3WlVpNThBK2lvMVl3VkRBT0JnTlZIUThCQWY4RUJBTUNCYUF3RXdZRFZSMGxCQXd3Q2dZSUt3WUIKQlFVSEF3SXdEQVlEVlIwVEFRSC9CQUl3QURBZkJnTlZIU01FR0RBV2dCUVNXelJjV1RObThXaWRuNkZFUzMzTgpQR1NjeHpBTkJna3Foa2lHOXcwQkFRc0ZBQU9DQVFFQUpoV3dXc29jdElVWFMrZ1ZmSFNRMlRwUXYvY0VSLzByCkJZS3hRcGkzMmlqOUlQOWZsVjFwSTVzbzdvSmJ5b0xEL1hvM3FmWkluUG5EK2RkM28rdWJRazBkNFhjcjg2MFMKSEJVcjc3K2YwOENlQUVRNm4zU2NQTE5uQkxkcXp4VG00bWx1QjllVHpqb1lrbGUyZm84cTd2N0tMSVZNdnZQZApJSlJpMnh5dm16SVRBYWM0emZrSCtmTEg2Z3NrRnIyY0V6djZVbHNCSjZjUU0vNFdEZnVzeER1ODZEYWw5ZHdpCmkyQ1k2Q3Q2WlVYL0VibW00c004ODN3TERvMWV0cjRSVlNtK3NzNkIrOUNYbVJ1NXZGa2diNTJPUVYwNjFEbm8KcUZkMFpLZlFhMGplUmFqVWY0eGR6VUVuMUdVSjZuVlZISHlCUFUxRzl2d3BEaTV1ZldVMmdRPT0KLS0tLS1FTkQgQ0VSVElGSUNBVEUtLS0tLQo= conditions: - lastTransitionTime: "2026-03-19T11:53:12Z" lastUpdateTime: "2026-03-19T11:53:12Z" message: Auto-approved CSR "system:openshift:openshift-authenticator-kxdbx" reason: AutoApproved status: "True" type: Approved