Ask Your Question
0

Did not receive certifcate

asked 2014-07-16 03:21:13 -0600

kemra102 gravatar image

On a couple of nodes I am getting an entry like this in the logs:

Jul 16 09:08:36 database puppet-agent[20025]: Did not receive certificate

From another post on StackOverflow I saw that sometimes this is due to the /etc/hosts not being correctly populated. In no cases has this fixed the issue for me.

It is odd that the hostname showed in the logs is an old hostname for each server. However each server had their certificate re-generated after each had their hostnames changed. The hostnames were also correctly updated in both /etc/hosts & /etc/sysconfig/network.

A manual Puppet run via a puppet agent -t runs fine, it's only when the daemon tries to call to the master that this error is produced.

edit retag flag offensive close merge delete

1 Answer

Sort by ยป oldest newest most voted
0

answered 2016-06-15 03:27:17 -0600

Tozz gravatar image

This happens then the Puppet daemon believes the system hostname is different from the hostname mentioned in the client certificates. It then generates new certificates which are not signed on the Puppetmaster. This is the cause for the error "Did not receive certificate".

We've seen OpenVZ VMs have their hostname changed after a reboot, caused by updates in the OpenVZ packages. There were some changes to do/dont include the domainname in the VM hostname. eg. server1.example.com would become server1 and vice versa.

The solution is either to check why the hostname has changed and resolve that. Or simply sign the new certificates on the Puppetmaster by running "puppet cert sign --all".

If a manual run does work, it looks to me the Puppet daemon has a incorrect/old hostname in its memory. Perhaps a restart of the daemon resolves the issue? Whatever the reason, it is caused by hostname changes on the puppet agent node.

edit flag offensive delete link more

Your Answer

Please start posting anonymously - your entry will be published after you log in or create a new account.

Add Answer

Question Tools

Stats

Asked: 2014-07-16 03:21:13 -0600

Seen: 460 times

Last updated: Jun 15 '16