官术网_书友最值得收藏!

Using autosign

In cryptography, as in life, you have to be careful what you sign. Normally, when you introduce a new client to the Puppetmaster, you need to generate a certificate request on the client, and then sign it on the master. However, you can skip this step by enabling autosigning.

How to do it...

Create the file /etc/puppet/autosign.conf on the Puppetmaster with the following contents: *.example.com

How it works...

Puppet checks any incoming certificate requests to see if they match a line from autosign.conf. Any certificate requests from clients with a hostname matching *.example.com will be automatically signed by the Puppetmaster.

Tip

Important: This is a potential security problem, since it amounts to trusting any client that can connect to the Puppetmaster. For this reason, autosigning is not recommended. If you do use it, make sure that the Puppetmaster is protected by a firewall that allows only approved clients or IP ranges to connect. A more secure approach is pre-signing.

See also

  • Pre-signing certificates in this chapter
主站蜘蛛池模板: 博湖县| 衡东县| 兴化市| 通道| 沙洋县| 兴义市| 南投市| 玛多县| 香港| 龙口市| 深水埗区| 勃利县| 宜州市| 称多县| 开封市| 宁明县| 会东县| 会东县| 成都市| 桂平市| 建宁县| 灵寿县| 墨江| 海淀区| 房产| 梅河口市| 南木林县| 开平市| 阿鲁科尔沁旗| 灵丘县| 墨竹工卡县| 丰顺县| 大同市| 南雄市| 普洱| 丹江口市| 桑日县| 玉门市| 昌邑市| 子长县| 绩溪县|