Announce: puppetlabs-certregen 0.1.1 available

21 views
Skip to first unread message

Adrien Thebo

unread,
Jan 24, 2017, 3:23:22 PM1/24/17
to puppet-...@googlegroups.com, puppet...@googlegroups.com, puppe...@googlegroups.com
If your Puppet infrastructure has been in operation for a few years, you're probably approaching the expiration date of your CA certificate. Puppet relies in its internal PKI to communicate securely between agents and masters and if the CA certificate expires then your Puppet infrastructure is going to come to a screeching halt. By default Puppet generates certificates with a lifetime of 5 years, so if you're coming up on this date then you'll want to start thinking about regenerating your CA certificate. Regenerating all certificates in an average Puppet installation would be a great deal of work and 
would mean a lot of downtime; fortunately we've got a better solution.

We're pleased to announce the first public release of the puppetlabs-certregen module. The certregen module provides an easy way to regenerate and distribute expiring CA certificates with zero downtime. When you regenerate your CA certificate with the certregen module your existing CA key pair is reused. The regenerated CA certificate is effectively equivalent to the expiring CA certificate and preserves the validity of your existing certificates, so you can update and distribute your new CA certificate with no downtime.

We'd like to thank the Puppet Customer Success team and especially Zack Smith for testing and documenting the migration process that this module is based on.


The Puppet Forge module can be found here: https://forge.puppet.com/puppetlabs/certregen

Installation and usage instructions can be found here: https://github.com/puppetlabs/puppetlabs-certregen/blob/master/README.markdown

To track issues related to this release or report issues, see the certregen component of the MODULES JIRA project: https://tickets.puppetlabs.com/browse/MODULES/component/20300/

--
Adrien Thebo | Puppet
Reply all
Reply to author
Forward
0 new messages