Puppet生成新的证书列表

时间:2018-02-05 18:50:25

标签: google-cloud-platform puppet agent master

我为那些有同样问题的人创建这篇文章。

我在云CentOS7上,我搞砸了代理商的证书......现在我正在尝试用新的证书更新旧证书 - 删除所有旧版本并生成新版本。 任何帮助都感激不尽。 我的错误:

Warning: Unable to fetch my node definition, but the agent run will continue:
Warning: SSL_connect returned=1 errno=0 state=error: certificate verify failed: [ok for /CN=servercert]
Info: Retrieving pluginfacts
Error: /File[/opt/puppetlabs/puppet/cache/facts.d]: Failed to generate additional resources using 'eval_generate': 
SSL_connect returned=1 errno=0 state=error: certificate verify failed: [ok for /CN=servercert]
Error: /File[/opt/puppetlabs/puppet/cache/facts.d]: Could not evaluate: Could not retrieve file metadata for puppet
:///pluginfacts: SSL_connect returned=1 errno=0 state=error: certificate verify failed: [ok for /CN=servercert]
Info: Retrieving plugin
Error: /File[/opt/puppetlabs/puppet/cache/lib]: Failed to generate additional resources using 'eval_generate': SSL_
connect returned=1 errno=0 state=error: certificate verify failed: [ok for /CN=servercert]
Error: /File[/opt/puppetlabs/puppet/cache/lib]: Could not evaluate: Could not retrieve file metadata for puppet:///
plugins: SSL_connect returned=1 errno=0 state=error: certificate verify failed: [ok for /CN=servercert]
Error: Could not retrieve catalog from remote server: SSL_connect returned=1 errno=0 state=error: certificate verif
y failed: [ok for /CN=servercert]
Warning: Not using cache on failed catalog
Error: Could not retrieve catalog; skipping run
Error: Could not send report: SSL_connect returned=1 errno=0 state=error: certificate verify failed: [ok for /CN=se
rvercert]

1 个答案:

答案 0 :(得分:0)

您确实可以删除SSL目录并重新生成所有这些目录,它也可能是解决此问题的最有效方法。这在Puppet文档here

中得到了很好的介绍