Hello Shawn,
Am 29.11.2012 22:52, schrieb shoerner:
> Just getting my first puppet master set up and I am having a problem
> that I just do not know how to get past. For some reason, my certificate
> store keeps getting corrupted. Basically what happens is that the server
> will issue itself a valid certificate (after removing the 'bad' cert)
> and will run just fine. When I start puppetDB (I am pretty sure it
> happens around here) on the system though, running the command 'puppet
> ca list --all' on the PuppetMaster, I get the following:
>
> Error: The certificate retrieved from the master does not match the
> agent's private key.
> Certificate fingerprint: *<fingerprint removed>*
which command did you used to sign your client certificates?
At Puppet 2.7 i was using "puppetca list" and "puppetca sign
host.example.net".
So i thought that i could use "puppet ca list" and "puppet ca sign
host.example.net" at Puppet 3.0.1.
But, when the first Puppet client did a "puppet agent --test", the
puppet master created a private key for
host.example.net at
"/var/lib/puppet/ssl/private_keys".
So i assume that there is a difference between "puppet ca" and "puppet
cert".
When i use "puppet cert list" and "puppet cert sign
host.example.net",
there will be no private key created and the commands "puppet ca list
--all" and "puppet cert list --all" are working as expected.
Best regards, Dennis