There are situations where we would like to regenereate the SSL certificate for a certain machine. Usually this is because we want to change the hostnames in the certificate. This page describes this process.

Stop the puppetagent (and other puppetservices) on the client machines.

The first step is to stop the puppet agent on the machine which should get new certificates:

root@client.fqdn:~# systemctl stop puppet

If the machine is running other puppet services (like puppetserver or puppetdb) these should also be stopped:

root@client.fqdn:~# systemctl stop puppetdb
root@client.fqdn:~# systemctl stop puppetserver

Revoke the old certificate

Before a machine can retrieve new SSL certificates it need to have the old ones revoked. This is done with the sl2 CLI:

$ sl2 cert set --status revoking <FQDN>

# In most cases, there will be more than one cert for a given host. If so, you need to use the uuid instead of the fqdn
$ sl2 cert list | grep <FQDN> # Take note of the UUID that belongs to the cert with status SIGNED
$ sl2 cert set --status revoking <UUID-from-last-step>

This will trigger the revocation and deletion of the existing certificate.

Next up is to clear all old certificates from the puppet-client.

root@client.fqdn:~# rm -rf /etc/puppetlabs/puppet/ssl

Create a new certificate

To create the new certificate you first need to prepare shiftleader to accept a new CSR:

$ sl2 server set --status PUPPET-SIGN <Hostname>

Then you can trigger a new puppet-run on the server needing a new certificate. When the server dont have a certificate it will create a CSR and send it to the puppetca-machine. If it expects this certificate (ie: The host is in the PUPPET-SIGN state in shiftleader) the puppetca will create and sign a cert based on the CSR which the requesting server then can download:

root@client.fqdn:~# puppet agent --test --waitforcert 10

While this command is running you could sign the certificate.


Rembember to restart the puppet agent

root@clien.fqdn:~# systemctl start puppet