On Sat, 27 Oct 2018 at 01:44, Maggie Dreyer <[email protected]> wrote: > Assuming your intermediate CA was set up using `puppetserver ca setup`, the > important bits are: > 1) Delete the SSL dir on the agent > 2) Set CRL checking on the agent to "leaf" > 3) Copy the CA bundle from the master to the agent: > (master) /etc/puppetlabs/puppet/ssl/ca/ca_crt.pem -> (agent) > /etc/puppetlabs/puppet/ssl/certs/ca.pem > 4) Copy the CRL bundle from the master to the agent: > (master) /etc/puppetlabs/puppet/ssl/ca/ca_crl.pem -> (agent) > /etc/puppetlabs/puppet/ssl/crl.pem > 5) Do an agent run to generate a CSR and proceed as usual
Thanks, that has worked perfectly. -- Craig Holyoak IT Support @ Redlands College [email protected] http://www.redlands.qld.edu.au/ -- -- You received this message because you are subscribed to the Google Groups "Puppet Users" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/d/msgid/puppet-users/CAA540SyMdM-OwHQeU_M0WZRzyuafb-KFoaqftjSaegXX8JcEAQ%40mail.gmail.com. For more options, visit https://groups.google.com/d/optout.
