diff --git a/roles/kubernetes-apps/rotate_tokens/tasks/main.yml b/roles/kubernetes-apps/rotate_tokens/tasks/main.yml
index 59886c0bbddaa14b97a62cf906a055b4667973ac..347d1b4c2d2747a0451b37b300196ea63d6961a2 100644
--- a/roles/kubernetes-apps/rotate_tokens/tasks/main.yml
+++ b/roles/kubernetes-apps/rotate_tokens/tasks/main.yml
@@ -4,8 +4,8 @@
   register: default_token
   changed_when: false
   until: default_token.rc == 0
-  delay: 1
-  retries: 5
+  delay: 4
+  retries: 10
 
 - name: Rotate Tokens | Get default token data
   command: "{{ bin_dir }}/kubectl --kubeconfig /etc/kubernetes/admin.conf get secrets {{ default_token.stdout }} -ojson"
diff --git a/roles/network_plugin/calico/files/make-ssl-typha.sh b/roles/network_plugin/calico/files/make-ssl-typha.sh
index 67567e9ffd155862d9d96bf31117aeacd0dba60d..783eb181647cad51da67065fac05e7fe869ee5bb 100644
--- a/roles/network_plugin/calico/files/make-ssl-typha.sh
+++ b/roles/network_plugin/calico/files/make-ssl-typha.sh
@@ -59,7 +59,7 @@ tmpdir=$(mktemp -d /tmp/calico_typha_certs.XXXXXX)
 trap 'rm -rf "${tmpdir}"' EXIT
 cd "${tmpdir}"
 
-mkdir -p "${SSLDIR} ${CADIR}"
+mkdir -p ${SSLDIR} ${CADIR}
 
 # Root CA
 if [ -e "$CADIR/ca.key" ]; then