|
Currently, the Puppet agent can only request a certificate once and does not understand certificate expiration/renewal. Moreover when the client certificate expires the node is disconnected from the master, so certificate expiration is pretty catastrophic. Puppet agents should be able to detect when their certificate is expiring, submit a CSR, and attempt to retrieve a new certificate once the CSR has been signed.
|