puppet autosign and mco request_cert

37 views
Skip to first unread message

gustavo...@gmail.com

unread,
Jul 27, 2020, 6:06:23 PM7/27/20
to Choria Users
Hi,

Is there any security recommendation regarding Puppet certificate autosigning and "mco choria request_cert"? Basically, we have autosign=true for machine puppet agent certs, but we don't want this mechanism for choria client certificates.

Thank you

Matt Cahill

unread,
Jul 27, 2020, 7:10:39 PM7/27/20
to Choria Users
Using naive auto-signing is not recommended in a production environment.


At a bare minimum set up basic auto-signing with config that matches against your client's reported domain suffix (thus excluding choria certs).


Ideally you'd use an auto-signing executable to verify the validity of a signing request before signing it, via pre-shared key, static inventory etc.. That script can be set up to not mark choria certs for auto-signing.

cheers

Matt
Reply all
Reply to author
Forward
0 new messages