I am trying to set up a fairly standardized system where junior sysadmins are able to add new systems into the cfengine setup. I have most of the steps properly automated so that they do not need special access on the cfengine master server, except for the issue of the new client's public key.
I can't figure out a way to force cfservd to trust a range of IPs despite the examples given in the reference guide. I know what ranges of IPs I want to trust, but it seems to only trust pre-existing keys or individual IPs. (I can't afford to manually add every single IP). This is cfengine 3.1.15. I've tried tricks like ACLs on the /var/cfengine/ppkeys directory, but that causes complaints on the master server. Any suggestions or am I overthinking this? -- [EMAIL PROTECTED] Mark McCullough "To announce that there must be no criticism of the President, or that we are to stand by the President, right or wrong, is not only unpatriotic and servile, but is morally treasonable to the American public." (Theodore Roosevelt, 1918)
signature.asc
Description: This is a digitally signed message part
_______________________________________________ Help-cfengine mailing list Help-cfengine@gnu.org http://lists.gnu.org/mailman/listinfo/help-cfengine