force agent fqdn

144 views
Skip to first unread message

Michael Wörz

unread,
Apr 24, 2014, 4:06:50 AM4/24/14
to puppet...@googlegroups.com
Hello,

when the clients fqdn changes for example when joining to a NIS or AD Domain puppet agent fails to connect to puppet master.

root-> puppet agent -vt
info: Creating a new SSL key for a4tmwo003.a41.local
warning: peer certificate won't be verified in this SSL session
warning: peer certificate won't be verified in this SSL session
info: Creating a new SSL certificate request for a4tmwo003.a41.local
info: Certificate Request fingerprint (md5): F4:96:B8:BB:C5:CA:82:B0:8D:2E:23:9A:78:64:97:06
warning: peer certificate won't be verified in this SSL session
err: Could not request certificate: Could not intern from s: header too long
Exiting; failed to retrieve certificate and waitforcert is disabled
[a4tmwo003:~]09:56

But i want the identity of the client to stay  the same even when domainname changes.
how can i force the agent to use its hostname when connecting to the master

thanks

Martin Alfke

unread,
Apr 24, 2014, 4:10:20 AM4/24/14
to puppet...@googlegroups.com
Hi Michael,

you can add the certname config option to the agent section.
http://docs.puppetlabs.com/references/latest/configuration.html#certname

This allows you to set individual names instead of using the fqdn.

hth,

Martin
> --
> You received this message because you are subscribed to the Google Groups "Puppet Users" group.
> To unsubscribe from this group and stop receiving emails from it, send an email to puppet-users...@googlegroups.com.
> To view this discussion on the web visit https://groups.google.com/d/msgid/puppet-users/504865fa-1e1d-484e-be09-2ac57d31119e%40googlegroups.com.
> For more options, visit https://groups.google.com/d/optout.

Reply all
Reply to author
Forward
0 new messages