PE Console with non-Self Signed Certificate?

Can the PE's console have a non-self signed cert installed, or would that break the reporting?

If you mean something like a purchased cert, you can. You can just change the paths in /etc/puppetlabs/httpd/conf.d/puppetdashboard.conf: You’ll want to edit each of the following lines to reflect the path of the purchased cert:

SSLCertificateFile /path/to/your/purchasedcert/cert.pem

SSLCertificateKeyFile /path/to/your/privatekey/key.pem

SSLCertificateChainFile /path/to/your/cacert/ca_cert.pem

SSLCACertificateFile /path/to/your/cacert//ca_cert.pem

Afterwards, you’ll want to restart pe-httpd.

Make sure to leave the original pe-internal-dashboard cert, private key and CA certs in place.

I agree. I think that the cert configs for "talking" to the puppet master are in /etc/puppetlabs/puppet-dashboard/settings.yml, and the https cert configs are in /etc/puppetlabs/httpd/conf.d/puppetmaster.conf.

I've asked this question to support once, the answer was that it would break stuff.

Perhaps it has changed in the mean time, I'd be interested to know.

