Page MenuHomePhabricator

gitlab1004 - puppet cert revoked?
Closed, ResolvedPublic

Description

This machine is still "insetup" but for some reason can't run puppet as it should.

Why did this happen?


[gitlab1004:~] $ sudo puppet agent -tv
Error: request https://puppet:8140//puppet/v3/node/gitlab1004.wikimedia.org failed: SSL_read: sslv3 alert certificate revoked
Warning: Unable to fetch my node definition, but the agent run will continue:
Warning: SSL_read: sslv3 alert certificate revoked
Info: Retrieving pluginfacts
Error: request https://puppet:8140//puppet/v3/file_metadatas/pluginfacts failed: SSL_read: sslv3 alert certificate revoked
Error: /File[/var/lib/puppet/facts.d]: Failed to generate additional resources using 'eval_generate': SSL_read: sslv3 alert certificate revoked
Error: request https://puppet:8140//puppet/v3/file_metadata/pluginfacts failed: SSL_read: sslv3 alert certificate revoked
Error: /File[/var/lib/puppet/facts.d]: Could not evaluate: Could not retrieve file metadata for puppet:///pluginfacts: SSL_read: sslv3 alert certificate revoked
Info: Retrieving plugin
Error: request https://puppet:8140//puppet/v3/file_metadatas/plugins failed: SSL_read: sslv3 alert certificate revoked
Error: /File[/var/lib/puppet/lib]: Failed to generate additional resources using 'eval_generate': SSL_read: sslv3 alert certificate revoked
Error: request https://puppet:8140//puppet/v3/file_metadata/plugins failed: SSL_read: sslv3 alert certificate revoked
Error: /File[/var/lib/puppet/lib]: Could not evaluate: Could not retrieve file metadata for puppet:///plugins: SSL_read: sslv3 alert certificate revoked
Info: Loading facts
Error: request https://puppet:8140//puppet/v3/catalog/gitlab1004.wikimedia.org failed: SSL_read: sslv3 alert certificate revoked
Error: Could not retrieve catalog from remote server: SSL_read: sslv3 alert certificate revoked
Warning: Not using cache on failed catalog
Error: Could not retrieve catalog; skipping run
Error: request https://puppet:8140//puppet/v3/report/gitlab1004.wikimedia.org failed: SSL_read: sslv3 alert certificate revoked
Error: Could not send report: SSL_read: sslv3 alert certificate revoked
[gitlab1004:~] $

Event Timeline

Mentioned in SAL (#wikimedia-operations) [2022-05-26T21:15:10Z] <mutante> puppetmaster1001 - sudo puppet cert clean gitlab1004.wikimedia.org revoked cert with serial 9600 AND cert with serial 9694 - somehow agent got "cert revoked" before I did anything (T309259)

Mentioned in SAL (#wikimedia-operations) [2022-05-26T21:16:11Z] <mutante> gitlab1004 - rm -rf /var/lib/puppet/ssl (T309259)

Mentioned in SAL (#wikimedia-operations) [2022-05-26T21:17:08Z] <mutante> gitlab1004/puppetmaster1001 - create new signing request, sign new cert for puppet, fixed puppet run - T309259

Dzahn claimed this task.

Notice: /Stage[main]/Ferm/Service[ferm]/ensure: ensure changed 'stopped' to 'running' (corrective)
Info: /Stage[main]/Ferm/Service[ferm]: Unscheduling refresh on Service[ferm]
Notice: Applied catalog in 16.22 seconds