Splitting CA component off puppet master

Posted by Dennis LeMioux on Server Fault See other posts from Server Fault or by Dennis LeMioux
Published on 2012-10-15T02:32:13Z Indexed on 2012/10/15 3:42 UTC
Read the original article Hit count: 421

Filed under:

We are scaling our puppet infrastructure and would like to split off the CA component from the puppet master server to another server. Part of the change involves a servername change for the puppetmaster too. I'm no puppet expert but i'm at a point where I -think- we need to create a SAN cert with both the old and new names in it (to be safe), and then re-sign all the agent nodes all over again which is going to be a royal PITA. Is there a quicker/smarter way to do this? We already have hundreds of agent nodes out there and individually re-signing them will be an arduous task.

© Server Fault or respective owner

Related posts about puppet