Page MenuHomePhabricator

puppetise pupet server copy of the public ca.pem
Closed, ResolvedPublic

Description

When the puppet CA was rolled over it seems that the following file did not get updated. this is the file that the puppet masters sends to clients to use as for the public CA when they are registered as an agent. I have manually updated this certificate for now however we should puppetise it and ensure no other systems still have the expired certificate

Related Objects

Event Timeline

Restricted Application added a subscriber: Aklapper. · View Herald Transcript
jbond triaged this task as High priority.Jun 30 2020, 7:59 AM

Change 608565 had a related patch set uploaded (by Jbond; owner: John Bond):
[operations/puppet@production] puppetmaster::frontend: manage ca_cert.pem and fix types lookup calls

https://gerrit.wikimedia.org/r/c/operations/puppet/ /608565

Change 608565 had a related patch set uploaded (by Jbond; owner: John Bond):
[operations/puppet@production] puppetmaster::frontend: manage ca_cert.pem and fix types lookup calls

https://gerrit.wikimedia.org/r/c/operations/puppet/ /608565

Change 609186 had a related patch set uploaded (by Jbond; owner: John Bond):
[operations/puppet@production] puppetmaster::frontend: manage ca_cert.pem

https://gerrit.wikimedia.org/r/c/operations/puppet/ /609186

Change 608565 merged by Jbond:
[operations/puppet@production] puppetmaster::frontend: add hiera calls and type validation

https://gerrit.wikimedia.org/r/608565

Change 609186 merged by Jbond:
[operations/puppet@production] puppetmaster::frontend: manage ca_cert.pem

https://gerrit.wikimedia.org/r/609186