https://www.puppet.com/community logo
Join Slack
Powered by
# puppet
  • n

    nmaludy

    11/03/2022, 6:58 PM
    is there a way to setup puppetserver ca to use EC instead of RSA, specifically ECDSA?
  • n

    nmaludy

    11/03/2022, 7:02 PM
    is there a way to setup puppetserver ca to use EC instead of RSA?
  • n

    nmaludy

    11/03/2022, 7:04 PM
    i tried setting
    key_type=ec
    in
    /etc/puppetlabs/puppet/puppet.conf
    , no luck
  • c

    csharpsteen

    11/03/2022, 8:01 PM
    No. Puppet is hardcoded to using RSA in quite a few places.
  • n

    nmaludy

    11/03/2022, 8:02 PM
    gotcha, heads up FIPS on RHEL8+ disables RSA so, need to switch to EC
  • s

    Slackbot

    11/03/2022, 8:04 PM
    This message was deleted.
    b
    c
    • 3
    • 3
  • y

    Yorokobi

    11/03/2022, 8:04 PM
    FIPS 140-2 ruins everything. šŸ˜†
  • n

    nmaludy

    11/03/2022, 8:05 PM
    can confirm haha
  • y

    Yorokobi

    11/03/2022, 8:05 PM
    "Sweet! I can upgrade RHEL 7 to 8 without replacing the OS."
    FIPS not supported.
    angry cry
  • d

    Dr Bunsen Honeydew

    11/03/2022, 8:45 PM
    allthethings šŸ§‘ā€šŸ«PE Console is about to start up in #CFD8Z9A4T
  • n

    natemccurdy

    11/03/2022, 9:06 PM
    Couple of questions… First, when running
    puppet apply
    what’s the best way to get the generated catalog stored on disk? I got it working with
    catalog_cache_terminus = json
    and
    client_datadir = <some_path>
    specified in puppet.conf. But that causes a problem, which leads to my 2nd question… Is
    --no-use_cached_catalog
    expected to work with
    puppet apply
    ? It doesn’t appear to be since the debug output always shows ā€œusing cached catalog for ā€¦ā€ due to those settings in my first question.
  • s

    Slackbot

    11/04/2022, 1:43 AM
    This message was deleted.
    n
    a
    n
    • 4
    • 7
  • s

    Slackbot

    11/04/2022, 11:14 AM
    This message was deleted.
    f
    d
    +2
    • 5
    • 10
  • d

    David Sandilands

    11/04/2022, 11:22 AM
    One approach we have seen is where people setup mutual trust between CAS on different Puppet Infrastructures using https://github.com/fervidus/puppet_ca_utils Allowing agents to be transfered between thewm
  • d

    David Sandilands

    11/04/2022, 11:22 AM
    One approach we have seen is where people setup mutual trust between CAS on different Puppet Infrastructures using https://github.com/fervidus/puppet_ca_utils Allowing agents to be transferred between them
  • j

    John Bond

    11/04/2022, 1:14 PM
    fyi "Internal Server Error - Request ID: 01GH1CDQBZS4N8DNECFYWK46T4" for https://puppet.com/docs/puppet/7/lang_data_number.html
  • s

    Slackbot

    11/04/2022, 4:01 PM
    This message was deleted.
    šŸ‘ 2
    ā¤ļø 3
    r
    • 2
    • 1
  • s

    Slackbot

    11/04/2022, 4:27 PM
    This message was deleted.
    n
    • 2
    • 1
  • s

    Slackbot

    11/04/2022, 5:19 PM
    This message was deleted.
    b
    • 2
    • 1
  • f

    Febu

    11/04/2022, 5:59 PM
    message has been deleted
  • s

    Slackbot

    11/04/2022, 7:53 PM
    This message was deleted.
    b
    • 2
    • 1
  • s

    Slackbot

    11/04/2022, 10:08 PM
    This message was deleted.
    y
    b
    +2
    • 5
    • 12
  • w

    William Myers

    11/04/2022, 10:41 PM
    Oof, what would one usually do when they encounter a module like this which expect a very stale version of libraries? https://forge.puppet.com/modules/puppet/sslcertificate/dependencies
  • w

    William Myers

    11/04/2022, 10:42 PM
    Especially when a lot of stuff is dependant upon stdlib
  • n

    natemccurdy

    11/04/2022, 10:42 PM
    Which libraries are you referring to?
  • w

    William Myers

    11/04/2022, 10:42 PM
    • puppetlabs/stdlib (>= 4.13.1 < 7.0.0)puppetlabs/powershell (>= 1.1.1 < 3.0.0)
  • w

    William Myers

    11/04/2022, 10:43 PM
    current stdlib is 8.5.0, powershell 5.2.0
  • n

    natemccurdy

    11/04/2022, 10:43 PM
    Oh. I’d just ignore that, personally. I’d deploy the module to a new Puppet environment, ignoring any dependent module specifications, test its functionality, and then deploy to
    production
    after that.
  • n

    natemccurdy

    11/04/2022, 10:44 PM
    Oh. I’d just ignore that, personally. I’d deploy the module to a new Puppet environment, ignoring any dependent module specifications, test its functionality, and then deploy to
    production
    after that.
  • w

    William Myers

    11/04/2022, 10:44 PM
    ignore dependencies then?
1...226227228...428Latest