There are situations where we would like to regenereate the SSL certificate for a certain machine. Usually this is because we want to change the hostnames in the certificate. This page describes this process.

Stop the puppetagent (and other puppetservices) on the client machines.

The first step is to stop the puppet agent on the machine which should get new certificates:

Stop the puppet agent
root@client.fqdn:~# systemctl stop puppet

If the machine is running other puppet services (like puppetserver or puppetdb) these should also be stopped:

Stop the puppet services
root@client.fqdn:~# systemctl stop puppetdb
root@client.fqdn:~# systemctl stop puppetserver

Revoke the old certificate

Before a machine can retrieve new SSL certificates it need to have the old ones revoked. This is done with the sl2 CLI:

Revoke old client certificate
$ sl2 cert set --status revoking <FQDN>

# In most cases, there will be more than one cert for a given host. If so, you need to use the uuid instead of the fqdn
$ sl2 cert list | grep <FQDN> # Take note of the UUID that belongs to the cert with status SIGNED
$ sl2 cert set --status revoking <UUID-from-last-step>

This will trigger the revocation and deletion of the existing certificate.

Next up is to clear all old certificates from the puppet-client.

Create a CSR
root@client.fqdn:~# rm -rf /etc/puppetlabs/puppet/ssl

Create a new certificate

To create the new certificate you first need to prepare shiftleader to accept a new CSR:

$ sl2 server set --status PUPPET-SIGN <Hostname>

Then you can trigger a new puppet-run on the server needing a new certificate. When the server dont have a certificate it will create a CSR and send it to the puppetca-machine. If it expects this certificate (ie: The host is in the PUPPET-SIGN state in shiftleader) the puppetca will create and sign a cert based on the CSR which the requesting server then can download:

Create a CSR
root@client.fqdn:~# puppet agent --test --waitforcert 10

While this command is running you could sign the certificate.


Rembember to restart the puppet agent

Start puppet agent
root@clien.fqdn:~# systemctl start puppet
  • No labels