On Sat, 27 Oct 2018 at 01:44, Maggie Dreyer <[email protected]> wrote:
> Assuming your intermediate CA was set up using `puppetserver ca setup`, the 
> important bits are:
> 1) Delete the SSL dir on the agent
> 2) Set CRL checking on the agent to "leaf"
> 3) Copy the CA bundle from the master to the agent:
> (master) /etc/puppetlabs/puppet/ssl/ca/ca_crt.pem -> (agent) 
> /etc/puppetlabs/puppet/ssl/certs/ca.pem
> 4) Copy the CRL bundle from the master to the agent:
> (master) /etc/puppetlabs/puppet/ssl/ca/ca_crl.pem -> (agent) 
> /etc/puppetlabs/puppet/ssl/crl.pem
> 5) Do an agent run to generate a CSR and proceed as usual

Thanks, that has worked perfectly.

-- 
Craig Holyoak
IT Support @ Redlands College
[email protected]
http://www.redlands.qld.edu.au/

-- 

-- 
You received this message because you are subscribed to the Google Groups 
"Puppet Users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/d/msgid/puppet-users/CAA540SyMdM-OwHQeU_M0WZRzyuafb-KFoaqftjSaegXX8JcEAQ%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.

Reply via email to