Ask Your Question

Revision history [back]

On which of the masters are you going to sign the client certificate signing request? You have two options: 1. you use one dedicated for signing and copy the ssl dir over to all puppet servers. 2. use a central ca which is responsible for signing, cleaning and revoking certificates.