PE Console with non-Self Signed Certificate?

asked 2012-12-20 14:02:12 -0600

arusso gravatar image

updated 2013-01-03 11:09:40 -0600

llowder gravatar image

Can the PE's console have a non-self signed cert installed, or would that break the reporting?

2 Answers

answered 2013-01-30 12:57:23 -0600

updated 2013-01-30 15:54:36 -0600

If you mean something like a purchased cert, you can. You can just change the paths in /etc/puppetlabs/httpd/conf.d/puppetdashboard.conf: You’ll want to edit each of the following lines to reflect the path of the purchased cert:

SSLCertificateFile /path/to/your/purchasedcert/cert.pem

SSLCertificateKeyFile /path/to/your/privatekey/key.pem

SSLCertificateChainFile /path/to/your/cacert/ca_cert.pem

SSLCACertificateFile /path/to/your/cacert//ca_cert.pem

Afterwards, you’ll want to restart pe-httpd.

Make sure to leave the original pe-internal-dashboard cert, private key and CA certs in place.

I agree. I think that the cert configs for "talking" to the puppet master are in /etc/puppetlabs/puppet-dashboard/settings.yml, and the https cert configs are in /etc/puppetlabs/httpd/conf.d/puppetmaster.conf.

Ancillas gravatar imageAncillas ( 2013-02-28 02:35:26 -0600 )edit

Could we please have this answer officially accepted? I found it very useful and also verified it with PuppetLabs support. Worked for me!

cbowles gravatar imagecbowles ( 2013-09-30 13:35:08 -0600 )edit

Apparently I can accept an answer on behalf of someone, so I did :).

Ancillas gravatar imageAncillas ( 2013-09-30 13:38:58 -0600 )edit

answered 2012-12-21 08:59:03 -0600

Ger Apeldoorn gravatar image

I've asked this question to support once, the answer was that it would break stuff.

Perhaps it has changed in the mean time, I'd be interested to know.

Asked: 2012-12-20 14:02:12 -0600

Seen: 348 times

Last updated: Jan 30 '13