decline a certificate request

Short question -- how do I respond "no" to a client certificate request?

Our puppet setup has been working fine. Suddenly, a misconfigured host makes a certificate request under the wrong name. The host has since been fixed and everything is fine, except that the puppet cert list command continues to show the outstanding incorrect request.

puppet cert clean wronghostname did not work. I get this error:

err: Could not call revoke: Could not find a serial number for wronghostname
Could not find a serial number for wronghostname

How do I tell puppet that I will never approve this request and it should stop asking?

Hi, I am not very sure because I didn't try this my own but I can give you few pointers: `puppet ca revoke wronghostname` `puppet ca destroy wronghostname` I hope, it will cover both answers.

Neither of these worked. It looks like nothing would work until I signed the cert. Thanks anyway.

Clean won't work because you haven't signed it yet.

I think because you don't really want this 'wrong host' on a revocation list, just do this:

# puppet cert sign wronghostname
# puppet cert clean wronghostname
