use of CNAMES and Puppet/Foreman

35 views
Skip to first unread message

Peter Berghold

unread,
Feb 12, 2015, 11:09:19 AM2/12/15
to puppet-users
Hi folks,

When I put my Foreman/Puppet architecture into production the requirement I am working against is to allow the use of "service names" instead of the fqdn of the host to access Puppet and Foreman. 

In my testing in my lab I have generated a cert against (I'm sanitizing here) the service name pocpuppet.{fqdn} which went well.  I put in the dns_alternate_names in puppet.conf (where's the right place for that? main?).

Everything seems to be going smoothly with puppet itself but for whatever reason the foreman-proxy is looking for the cert with the original fqdn of the host itself. 

I went into every foreman YAML file out there and put the service name in place of the hostname and it still is looking for the original server.  

Anybody else run into this?  Any thoughts. 

--

Peter L. Berghold                       Salty....@gmail.com

http://science-fiction.berghold.net

Reply all
Reply to author
Forward
0 new messages