Project

General

Profile

SSL » History » Revision 2

Revision 1 (Ohad Levy, 01/25/2011 08:24 AM) → Revision 2/11 (Corey Osman, 11/11/2011 06:15 PM)

h1. SSL setup 

 The smart proxy can work in SSL mode, where both sides verify and trust each other. 

 h2. Configure SSL certificates 

 This request will only be accepted if the SSL certificates match. Therefore the client's private key grants access to proxy's funtionality, so protect it. 

 As this tool is meant to interoperate with a puppet installation I suggest that you use the Certificate Authority provided by a puppet server as your CA. 

 # Login to your puppetmaster, which has a Certificate Authority 
 # Use the puppet tools to create a new certificate 
 <pre><code> 
   puppetca --generate <proxy-FQDN> 
 </pre></code> 
 # Copy the certificate keys to your Windows host 
 <pre><code> 
     scp puppetmaster:/var/lib/puppet/ssl/ca/signed/<proxy-FQDN>.pem signed.pem 
     scp puppetmaster:/var/lib/puppet/ssl/private_keys/<proxy-FQDN>.pem private.pem 
 </pre></code> 
 # Copy the ssl/certs/ca.pem from any puppet client to the smart-proxy\config directory. This ensures that the proxy trusts the same CA as a puppet client. 

 h2. Troubleshooting 

 <pre> 
 Unable to save 
 Unable to communicate with the proxy: No such file or directory - /.puppet/var/ssl/certs/foremanserver.domainname.corp.pem 
 Please check the proxy is configured and running on the host before saving. 
 </pre>