Trevor Vaughan wrote:
> I was doing some thinking and reading through the posts on the Apache
> CRL issue with puppet and realized that people were suggesting changing
> the wrong host value.
> 
> Fundamentally, the CN in the CA cert is irrelevant. In theory, you never
> hit that server live so it makes no difference if it were all called "bob".
> 
> So, at least in the 0.24.9 series, if you change line 158 of
> 
> /usr/lib/ruby/site_ruby/1.8/puppet/sslcertificates/ca.rb
> 
> From:
> 
> name = Facter["hostname"].value
> 
> To:
> 
> name = Facter["hostname"].value + "-something_sane"


Trevor

Do you remember which ticket this was?

Markus - your thoughts on making this change?

James

-- 
Puppet Labs - http://www.puppetlabs.com
C: 503-734-8571

-- 
You received this message because you are subscribed to the Google Groups 
"Puppet Developers" group.
To post to this group, send email to [email protected].
To unsubscribe from this group, send email to 
[email protected].
For more options, visit this group at 
http://groups.google.com/group/puppet-dev?hl=en.

Reply via email to