官术网_书友最值得收藏!

Using autosign

In cryptography, as in life, you have to be careful what you sign. Normally, when you introduce a new client to the Puppetmaster, you need to generate a certificate request on the client, and then sign it on the master. However, you can skip this step by enabling autosigning.

How to do it...

Create the file /etc/puppet/autosign.conf on the Puppetmaster with the following contents: *.example.com

How it works...

Puppet checks any incoming certificate requests to see if they match a line from autosign.conf. Any certificate requests from clients with a hostname matching *.example.com will be automatically signed by the Puppetmaster.

Tip

Important: This is a potential security problem, since it amounts to trusting any client that can connect to the Puppetmaster. For this reason, autosigning is not recommended. If you do use it, make sure that the Puppetmaster is protected by a firewall that allows only approved clients or IP ranges to connect. A more secure approach is pre-signing.

See also

  • Pre-signing certificates in this chapter
主站蜘蛛池模板: 麻江县| 新野县| 临漳县| 苍山县| 沂南县| 深泽县| 南木林县| 新郑市| 迁西县| 巴彦淖尔市| 沈阳市| 昭通市| 勃利县| 鲁山县| 凤翔县| 井冈山市| 伽师县| 桦川县| 沛县| 绍兴县| 滨海县| 新野县| 随州市| 顺昌县| 固原市| 永靖县| 台北县| 基隆市| 惠水县| 揭东县| 商丘市| 颍上县| 苗栗市| 清镇市| 沙洋县| 罗田县| 台东市| 增城市| 高邮市| 绥棱县| 贞丰县|