There's a bug with old versions of kubeadm, in that it can update certificates, but doesn't correctly "wire them in".
Are you trying to connect to the cluster and getting:
$ kubectl <foo>
Unable to connect to the server: x509: certificate has expired or is not yet valid