There are situations where we would like to regenereate the SSL certificate for a certain machine. Usually this is because we want to change the hostnames in the certificate. This page describes this process.
Stop the puppetagent (and other puppetservices) on the client machines.
The first step is to stop the puppet agent on the machine which should get new certificates:
root@client.fqdn:~# systemctl stop puppet
If the machine is running other puppet services (like puppetserver or puppetdb) these should also be stopped:
root@client.fqdn:~# systemctl stop puppetdb root@client.fqdn:~# systemctl stop puppetserver
Revoke the old certificate
Before a machine can retrieve new SSL certificates it need to have the old ones revoked. This is done with the sl2 CLI:
$ sl2 cert set --status revoking <FQDN> # In most cases, there will be more than one cert for a given host. If so, you need to use the uuid instead of the fqdn $ sl2 cert list | grep <FQDN> # Take note of the UUID that belongs to the cert with status SIGNED $ sl2 cert set --status revoking <UUID-from-last-step>
This will trigger the revocation and deletion of the existing certificate.
Next up is to clear all old certificates from the puppet-client.
root@client.fqdn:~# rm -rf /etc/puppetlabs/puppet/ssl
Create a new certificate
To create the new certificate you first need to prepare shiftleader to accept a new CSR:
$ sl2 server set --status PUPPET-SIGN <Hostname>
Then you can trigger a new puppet-run on the server needing a new certificate. When the server dont have a certificate it will create a CSR and send it to the puppetca-machine. If it expects this certificate (ie: The host is in the PUPPET-SIGN state in shiftleader) the puppetca will create and sign a cert based on the CSR which the requesting server then can download:
root@client.fqdn:~# puppet agent --test --waitforcert 10
While this command is running you could sign the certificate.
Rembember to restart the puppet agent
root@clien.fqdn:~# systemctl start puppet