Re: [foreman-users] Katello 2.4 capsule load balancing

2017-07-16 Thread Andrew Schofield
Good news that everything else works. For puppet I have the LB name in the auth.conf file on the relevant allow lines. The cert for puppet have the lb name AND the name of the hosts sitting behind it in a SAN (Server Alternate Name) certificate. On 11 July 2017 at 12:01, Unix SA

Re: [foreman-users] Katello 2.4 capsule load balancing

2017-07-11 Thread Unix SA
Thanks, I am having issue with puppet, when i provision client i give puppet CA and master as CNAME now after succesful provision puppet.conf in client has cname as CA and server, but when i check capsule it has not generated certificates using cname and puppet communication fails, am i

Re: [foreman-users] Katello 2.4 capsule load balancing

2017-07-08 Thread Andrew Schofield
Yes, we have our capsules (4 per region) sitting behind load balancers using custom SSL. A few gotchas for Satellite: 1. katello-ca-consumer-latest sets subscription manager with the capsules hostname. So after the install of that rpm , we update the subscription manager config to the load

Re: [foreman-users] Katello 2.4 capsule load balancing

2017-07-07 Thread Unix SA
hey, did you get chance to test it ? On Friday, 6 May 2016 07:58:27 UTC+5:30, Andrew Schofield wrote: > > Apparently RH have a reference architecture for this. We are also testing > this shortly too. We will be migrating some 20k hosts to some 20 or so > Capsules! > > On Tuesday, April 5,