This message was deleted.
# office-hours
s
This message was deleted.
Puppet will use the hostname as its certname. If it doesn't have a cert for that name, it will start the cert request process.
aka, your hostname is changing
k
but - my hostname isn't changing. It's configured as <hostname> only. The only way a .lan or .home can be found is using like dns lookups or something like that. both hostname and hostname -f return simply <hostname> Is there a best practice to avoid this - maybe put a local /etc/hosts entry too or something?
b
Sorry. Will clarify. Per the docs
Defaults to the Host's fully qualified domain name, as determined by Facter
k
ahhh... the plot thickens
b
Aka,
facter fqdn
is reporting something different
👍 1
Facter has to guess sometimes because fqdn can be surprisingly non deterministic is some circumstances
k
well, facter fqdn also returns just <hostname>
b
Run as root, with a limited environment like a system service would have
k
no change, <hostname> everywhere, I even grepped facter for .lan and .home
y'know though - I could force the name in puppet.conf with that certname parameter set with <hostname> I bet.
b
if you know what you want the certname to be, then you can just specify it in puppet.conf https://www.puppet.com/docs/puppet/latest/config_about_settings.html
k
yep, that's what I'm trying now on one of these filthy machines
welp, that didn't work either - I put the certname parameter under the [agent] section. Maybe put it under the [server] section? I dunno man, this is nuts
g
certname should be under [main] section in the agent's puppet.conf https://www.puppet.com/docs/puppet/8/config_file_main.html
👀 1
b
There's a reason facter looks for the FQDN, not hostname. There's a bigger chance that the FQDNs are unique across all your servers, the hostname isn't
and you can only have one certificate per common name. So a certificate for the FQDN is recommended
I would never set certname to a hostname
👍 1
agreed 1
k
agreed - but for our small 'test' network, this would be fine. But yea, for our main 'prod' network, for sure. Thanks!