Jira (PUP-11602) Change default crl_refresh_interval to 1 day in puppet 8

21 views
Skip to first unread message

Josh Cooper (Jira)

unread,
Jul 29, 2022, 11:42:02 AM7/29/22
to puppe...@googlegroups.com
Josh Cooper created an issue
 
Puppet / Improvement PUP-11602
Change default crl_refresh_interval to 1 day in puppet 8
Issue Type: Improvement Improvement
Assignee: Unassigned
Created: 2022/07/29 8:41 AM
Fix Versions: PUP 8.0.0
Priority: Normal Normal
Reporter: Josh Cooper

The crl_refresh_interval setting was added in Puppet 6.5 (PUP-2310) and defaults to never, so it's behind a feature flag. Now that it's been in use for awhile and is generally a good thing security-wise, this ticket is to change the default value to 1 day. This is a simple change to lib/puppet/defaults.rb and should be done for the 8.0 release. See https://puppetcommunity.slack.com/archives/C0W1X7ZAL/p1659103057731379

Add Comment Add Comment
 
This message was sent by Atlassian Jira (v8.20.11#820011-sha1:0629dd8)
Atlassian logo

Josh Cooper (Jira)

unread,
Sep 2, 2022, 3:20:02 PM9/2/22
to puppe...@googlegroups.com

Josh Cooper (Jira)

unread,
Sep 12, 2022, 2:20:01 PM9/12/22
to puppe...@googlegroups.com

Morgan Rhodes (Jira)

unread,
Dec 8, 2022, 1:26:02 PM12/8/22
to puppe...@googlegroups.com

Morgan Rhodes (Jira)

unread,
Jan 4, 2023, 1:10:03 PM1/4/23
to puppe...@googlegroups.com

Morgan Rhodes (Jira)

unread,
Jan 4, 2023, 1:24:02 PM1/4/23
to puppe...@googlegroups.com
Morgan Rhodes updated an issue
The crl_refresh_interval setting was added in Puppet 6.5 (PUP-2310) and defaults to never, so it's behind a feature flag. Now that it's been in use for awhile and is generally a good thing security-wise, this ticket is to change the default value to 1 day. This is a simple change to lib/puppet/defaults.rb and should be done for the 8.0 release. See https://puppetcommunity.slack.com/archives/C0W1X7ZAL/p1659103057731379


May also include some test changes.

Michael Hashizume (Jira)

unread,
Jan 4, 2023, 5:08:01 PM1/4/23
to puppe...@googlegroups.com

Michael Hashizume (Jira)

unread,
Apr 12, 2023, 4:36:03 PM4/12/23
to puppe...@googlegroups.com
Michael Hashizume updated an issue
Change By: Michael Hashizume
Release Notes: Enhancement
Release Notes Summary: puppet-agent now defaults to refreshing its certificate revocation list (CRL) once every 24 hours.

Parker Leach (Jira)

unread,
Apr 19, 2023, 2:49:04 PM4/19/23
to puppe...@googlegroups.com
Reply all
Reply to author
Forward
0 new messages