Regards,
Maybe look into running masterless to avoid problems with certs. Just run puppet apply on the new server.
--
You received this message because you are subscribed to the Google Groups "Puppet Users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to puppet-users...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/puppet-users/52CE6F14.7060508%40cscs.ch.
For more options, visit https://groups.google.com/groups/opt_out.
To view this discussion on the web visit https://groups.google.com/d/msgid/puppet-users/CACzr%3DFc4fKWeGA%3Dz%2B0taUdCognf7mjoReqCTj-WHm7mvachBvQ%40mail.gmail.com.
Autosign will be not enough, since if server has already signed - it will show cert mismatch.
you can trigger cert clean every time you reimage server.
To view this discussion on the web visit https://groups.google.com/d/msgid/puppet-users/52CE98CA.3070206%40cscs.ch.
Thanks for your suggestions,
Running masterless is a bit too exotic, since we would like to use all those nice features that make a Puppet installation complete: specially hiera searches and PuppetDB. Modules, too, should be compatible with other clusters, so no big deviations can occur.
Enabling auto-sign, as Jose Luis suggested, may be a possibility. I have just checked myself if autosign works if the same node was already registered in the CA... but according to the documentation it does not look like it, not to mention the security issues that come with it.
Does the certificate name need to match the fqdn for puppet to allow connections?
--
You received this message because you are subscribed to the Google Groups "Puppet Users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to puppet-users...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/puppet-users/3c8f53f8-09a2-4bd8-8fa8-1986efdafeb3%40googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/puppet-users/52CEBC6A.3070403%40cscs.ch.
I understand your point. I guess the SSL layer will render the request as illegitimate, but even if it doesn't, it may be playing with fire :)
To view this discussion on the web visit https://groups.google.com/d/msgid/puppet-users/52CEBC6A.3070403%40cscs.ch.
Thanks for your suggestions,
Running masterless is a bit too exotic, since we would like to use all those nice features that make a Puppet installation complete: specially hiera searches and PuppetDB. Modules, too, should be compatible with other clusters, so no big deviations can occur.
Enabling auto-sign, as Jose Luis suggested, may be a possibility. I have just checked myself if autosign works if the same node was already registered in the CA... but according to the documentation it does not look like it, not to mention the security issues that come with it.
To view this discussion on the web visit https://groups.google.com/d/msgid/puppet-users/52CF2955.2000306%40bericotechnologies.com.