The major components of Puppet Enterprise (the Puppet master, PuppetDB, and PE console) contain SSL certificates and security credentials (private and public keys) that are generated by PE’s built-in certificate authority (CA). The following document provides instructions on regenerating the cert and security credentials for the Puppet master.
Regenerating certificates and security credentials for the Puppet master involves the following steps:
Important: This document applies to the certs and security credentials for the Puppet master server only. If you’ve experienced an unforeseen security vulnerability and need to regenerate all the certificates and security credentials in your infrastructure, refer to Regenerating certs and security credentials in split Puppet Enterprise deployments for complete instructions.
This guide also applies to split installations only. On monolithic installs, PuppetDB shares an agent cert and security credentials with the Puppet master and the PE console. For a monolithic install, you must regenerate all certs and security credentials.
Finally, this document should not be used to regenerate certificates for LEI compile masters.
Notes and warnings:
You must be logged in as a root, (or in the case of Windows agents, as an account with Administrator Privileges) to make these changes.
If you encounter any errors during steps that involve
chmodcommands, you should diagnose these before continuing, as the success each step is very important to the success of the next step.
In the following instructions, when
<CERTNAME>is used, it refers to the Puppet master’s certname. To find this value, run
puppet config print certnamebefore starting.
Unless otherwise indicated, all commands are run on the Puppet master server.
To clear and regenerate certs on your Puppet master:
Back up the
If something goes wrong, you may need to restore these directories so your deployment can stay functional. However, if you needed to regenerate your certs for security reasons and couldn’t, you should contact Puppet support as soon as you restore service so we can help you secure your site.
Shut down all PE-related services with the following commands:
puppet resource service puppet ensure=stopped puppet resource service pe-puppetserver ensure=stopped puppet resource service pe-activemq ensure=stopped puppet resource service mcollective ensure=stopped puppet resource service pe-orchestration-services ensure=stopped puppet resource service pxp-agent ensure=stopped
Clear the cert and security credentials for the Puppet master.
puppet cert clean <CERTNAME>
Remove the cached catalog.
rm -f /opt/puppetlabs/puppet/cache/client_data/catalog/<CERTNAME>.json
Generate the Puppet master’s new certs.
puppet cert generate <CERTNAME> --dns_alt_names=<DNS_ALT_NAMES>
Note: Be sure to specify any dns alt names you have. You can find the list of your current dns alt names with
puppet cert list <CERTNAME>. By default, PE uses
Copy the new cert and security credentials to the orchestration-services cert directory.
cp /etc/puppetlabs/puppet/ssl/certs/<CERTNAME>.pem /etc/puppetlabs/orchestration-services/ssl/<CERTNAME>.cert.pem cp /etc/puppetlabs/puppet/ssl/public_keys/<CERTNAME>.pem /etc/puppetlabs/orchestration-services/ssl/<CERTNAME>.public_key.pem cp /etc/puppetlabs/puppet/ssl/private_keys/<CERTNAME>.pem /etc/puppetlabs/orchestration-services/ssl/<CERTNAME>.private_key.pem openssl pkcs8 -topk8 -inform PEM -outform DER -in /etc/puppetlabs/orchestration-services/ssl/<CERTNAME>.private_key.pem -out /etc/puppetlabs/orchestration-services/ssl/<CERTNAME>.private_key.pk8 -nocrypt chown -R pe-orchestration-services:pe-orchestration-services /etc/puppetlabs/orchestration-services/ssl/
Create the orchestration-services .pk8 cert.
cd /etc/puppetlabs/orchestration-services/ssl openssl pkcs8 -topk8 -inform PEM -outform DER -in /etc/puppetlabs/orchestration-services/ssl/<CERTNAME>.private_key.pem -out /etc/puppetlabs/orchestration-services/ssl/<CERTNAME>.private_key.pk8 -nocrypt chown -R pe-orchestration-services:pe-orchestration-services /etc/puppetlabs/orchestration-services/ssl/
Restart all PE-related services with the following commands:
puppet resource service puppet ensure=running puppet resource service pe-puppetserver ensure=running puppet resource service pe-activemq ensure=running puppet resource service mcollective ensure=running puppet resource service pe-orchestration-services ensure=running puppet resource service pxp-agent ensure=running