Project

General

Profile

Actions

Feature #700

closed

Build link doesn't remove the puppetca corresponding to the host

Added by Arnaud Sourioux about 13 years ago. Updated almost 13 years ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Category:
PuppetCA
Target version:
-
Difficulty:
Triaged:
Fixed in Releases:
Found in Releases:

Description

When i try to build a host wich already has been connected to the puppetmaster,
so he already has a puppet certificate,
the puppet's host certificate should be remove,
or after the build completion when the host will try to connect to the puppetmaster,
he will receive an error and won't be able to communicate
at this time we have to delete it by hand everytime we want to rebuild a host.

ps : i don't really know if it is able to do it in foreman or if it must be asked to the puppet developper team

Actions #1

Updated by Ohad Levy about 13 years ago

  • Status changed from New to Feedback
  • Assignee deleted (Ohad Levy)

Foreman executes a puppetca --clean once the host requires a kickstart/preseed file.

I think that should be enough to allow for the host to generate a new certificate request.

Actions #2

Updated by Arnaud Sourioux about 13 years ago

It should be ok with a puppetca --clean $fqdn
but I can't load the /unattended/provision?spoof<% @host.ip %> in my PXELinux file
(explained here Support #706)

Actions #3

Updated by Ohad Levy almost 13 years ago

  • Status changed from Feedback to Closed

thats correct, using spoof puppetca is not being called.

Actions

Also available in: Atom PDF