On 02/20/2013 02:38 PM, spankthes...@gmail.com wrote: > Ah, right. I forgot step 5. Which is replacing the CA with one created > using openssl. Of course, all other certs are obsolete after you do > that, so you can use your shiny new process of certifying agents to > make > them new ones. > > > Great, except I tried that and failed, therefore this thread ;) I was > hoping someone was doing something like that already and know if its > possible, and if it is, how to do it properly.
Well, I disbelieve this has been done, because the way you are proposing to model puppet architecture sounds pretty unique. As I understood, you tried to do steps 1 through 5 in one, which failed. I can think of quite some ways this would happen. Therefor the baby steps. HTH, Felix -- You received this message because you are subscribed to the Google Groups "Puppet Users" group. To unsubscribe from this group and stop receiving emails from it, send an email to puppet-users+unsubscr...@googlegroups.com. To post to this group, send email to puppet-users@googlegroups.com. Visit this group at http://groups.google.com/group/puppet-users?hl=en. For more options, visit https://groups.google.com/groups/opt_out.