Re: [Puppet Users] PE 2019.2 with Puppet Agent 5.x (Turn off new Intermediate CA architecture)

2019-11-17 Thread A Manzer
>From what I saw, the new architecture is an Intermediate Signing Cert, signed by a bare *key*. I'm not sure how I could copy that to an agent and have it trusted. turn off your master, delete your ssldir and restart it to have it create a > self signed root. > This is what I want to do! But

Re: [Puppet Users] PE 2019.2 with Puppet Agent 5.x (Turn off new Intermediate CA architecture)

2019-11-19 Thread Justin Stoller
sorry for the delay, kid got sick. On Sun, Nov 17, 2019 at 3:13 AM A Manzer wrote: > From what I saw, the new architecture is an Intermediate Signing Cert, > signed by a bare *key*. I'm not sure how I could copy that to an agent > and have it trusted. > The $cadir/ca_crt.pem will contain both

Re: [Puppet Users] PE 2019.2 with Puppet Agent 5.x (Turn off new Intermediate CA architecture)

2019-11-22 Thread A Manzer
Thanks Justin. I think I was just Out Of Luck from the start, by starting with a PE 2019.2 install, with only 5.x agents available. For anyone who finds this in the future, what I ended up doing was using the Puppet *gem* on Raspbian. I ended up essentially following this guide