Hi
Install puppet master and puppet client on two difference boxes .
Puppet master is started perfectly , but while connecting puppet client to
puppet master we are getting below error .
Puppet master hosts file .
127.0.0.1 localhost.localdomain localhost
::1 localhost6.localdomain6 localhost6
10.6.122.207 finnairportal.itcinfotech.com finnairportal
Puppet client hosts file
127.0.0.1 devopstest localhost.localdomain localhost
::1 devopstest localhost6.localdomain6 localhost6
10.6.122.206 devopstest puppetmaster puppet devopstest.itcinfotech.com
10.6.122.207 finnairportal.itcinfotech.com
Puppet.conf master file
[root@finnairportal ~]# cat /etc/puppetlabs/puppet/puppet.conf
[main]
certname = finnairportal.itcinfotech.com
vardir = /var/opt/lib/pe-puppet
logdir = /var/log/pe-puppet
rundir = /var/run/pe-puppet
modulepath =
/etc/puppetlabs/puppet/modules:/opt/puppet/share/puppet/modules
server = finnairportal.itcinfotech.com
user = pe-puppet
group = pe-puppet
archive_files = true
archive_file_server = finnairportal.itcinfotech.com
[master]
certname = finnairportal.itcinfotech.com
dns_alt_names =
finnairportal,finnairportal.itcinfotech.com,puppet,puppet.itcinfotech.com
ca_name = 'Puppet CA generated on finnairportal.itcinfotech.com at
2013-09-24 14:13:35 +0530'
reports = http,puppetdb
reporturl = https://localhost:443/reports/upload
node_terminus = exec
external_nodes = /etc/puppetlabs/puppet-dashboard/external_node
ssl_client_header = SSL_CLIENT_S_DN
ssl_client_verify_header = SSL_CLIENT_VERIFY
storeconfigs_backend = puppetdb
storeconfigs = true
[agent]
report = true
classfile = $vardir/classes.txt
localconfig = $vardir/localconfig
graph = true
pluginsync = true
environment = production
This is puppet.conf client file .
[root@devopstest ssl]# cat /etc/puppetlabs/puppet/puppet.conf
[main]
certname = devopstest
vardir = /var/opt/lib/pe-puppet
logdir = /var/log/pe-puppet
rundir = /var/run/pe-puppet
modulepath =
/etc/puppetlabs/puppet/modules:/opt/puppet/share/puppet/modules
server = devopstest
user = pe-puppet
group = pe-puppet
archive_files = true
archive_file_server = devopstest
[master]
certname = finnairportal.itcinfotech.com
dns_alt_names = finnairportal.itcinfotech.com,puppet
ca_name = 'Puppet CA generated on devopstest at 2013-09-12 01:19:26
+0530'
reports = http,puppetdb
reporturl = https://localhost:443/reports/upload
node_terminus = exec
external_nodes = /etc/puppetlabs/puppet-dashboard/external_node
ssl_client_header = SSL_CLIENT_S_DN
ssl_client_verify_header = SSL_CLIENT_VERIFY
storeconfigs_backend = puppetdb
storeconfigs = true
[agent]
report = true
classfile = $vardir/classes.txt
localconfig = $vardir/localconfig
graph = true
pluginsync = true
environment = production
We are using below command to connect client to puppet master and getting
error .
puppet agent --server finnairportal.itcinfotech.com --waitforcert 60 --test
Error :-
[root@devopstest ~]# puppet agent --server finnairportal.itcinfotech.com
–waitforcert 60 --test
Info: Creating a new SSL key for devopstest
Info: Creating a new SSL certificate request for devopstest
Info: Certificate Request fingerprint (SHA256):
70:05:A8:13:3D:20:FD:64:2E:B8:16:F9:24:B8:8A:37:11:9B:83:FC:0C:38:3C:68:4F:6A:5C:DC:C1:5F:81:11
Notice: Did not receive certificate
Info: Caching certificate for devopstest
Warning: Unable to fetch my node definition, but the agent run will
continue:
Warning: SSL_connect returned=1 errno=0 state=SSLv3 read server certificate
B: certificate verify failed: [self signed certificate in certificate chain
for /CN=Puppet CA generated on finnairportal.itcinfotech.com at 2013-09-24
14:13:35 +0530]
Info: Retrieving plugin
Error: /File[/var/opt/lib/pe-puppet/lib]: Failed to generate additional
resources using 'eval_generate: SSL_connect returned=1 errno=0 state=SSLv3
read server certificate B: certificate verify failed: [self signed
certificate in certificate chain for /CN=Puppet CA generated on
finnairportal.itcinfotech.com at 2013-09-24 14:13:35 +0530]
Error: /File[/var/opt/lib/pe-puppet/lib]: Could not evaluate: SSL_connect
returned=1 errno=0 state=SSLv3 read server certificate B: certificate
verify failed: [self signed certificate in certificate chain for /CN=Puppet
CA generated on finnairportal.itcinfotech.com at 2013-09-24 14:13:35 +0530]
Could not retrieve file metadata for
puppet://finnairportal.itcinfotech.com/plugins: SSL_connect returned=1
errno=0 state=SSLv3 read server certificate B: certificate verify failed:
[self signed certificate in certificate chain for /CN=Puppet CA generated
on finnairportal.itcinfotech.com at 2013-09-24 14:13:35 +0530]
Info: Loading facts in
/opt/puppet/share/puppet/modules/pe_common/lib/facter/windows.rb
Info: Loading facts in
/opt/puppet/share/puppet/modules/stdlib/lib/facter/root_home.rb
Info: Loading facts in
/opt/puppet/share/puppet/modules/stdlib/lib/facter/puppet_vardir.rb
Info: Loading facts in
/opt/puppet/share/puppet/modules/stdlib/lib/facter/facter_dot_d.rb
Info: Loading facts in
/opt/puppet/share/puppet/modules/stdlib/lib/facter/pe_version.rb
Info: Loading facts in
/opt/puppet/share/puppet/modules/postgresql/lib/facter/postgres_default_version.rb
Info: Loading facts in
/opt/puppet/share/puppet/modules/concat/lib/facter/concat_basedir.rb
Info: Loading facts in
/opt/puppet/share/puppet/modules/pe_puppetdb/lib/facter/puppetdb_server_status.rb
Info: Loading facts in
/opt/puppet/share/puppet/modules/auth_conf/lib/facter/custom_auth_conf.rb
Info: Loading facts in
/opt/puppet/share/puppet/modules/firewall/lib/facter/ip6tables_version.rb
Info: Loading facts in
/opt/puppet/share/puppet/modules/firewall/lib/facter/iptables_version.rb
Info: Loading facts in
/opt/puppet/share/puppet/modules/firewall/lib/facter/iptables_persistent_version.rb
Info: Loading facts in /var/opt/lib/pe-puppet/lib/facter/custom_auth_conf.rb
Info: Loading facts in
/var/opt/lib/pe-puppet/lib/facter/ip6tables_version.rb
Info: Loading facts in /var/opt/lib/pe-puppet/lib/facter/root_home.rb
Info: Loading facts in /var/opt/lib/pe-puppet/lib/facter/puppet_vardir.rb
Info: Loading facts in /var/opt/lib/pe-puppet/lib/facter/iptables_version.rb
Info: Loading facts in /var/opt/lib/pe-puppet/lib/facter/facter_dot_d.rb
Info: Loading facts in /var/opt/lib/pe-puppet/lib/facter/concat_basedir.rb
Info: Loading facts in
/var/opt/lib/pe-puppet/lib/facter/puppetdb_server_status.rb
Info: Loading facts in
/var/opt/lib/pe-puppet/lib/facter/postgres_default_version.rb
Info: Loading facts in /var/opt/lib/pe-puppet/lib/facter/pe_version.rb
Info: Loading facts in
/var/opt/lib/pe-puppet/lib/facter/iptables_persistent_version.rb
Info: Loading facts in /var/opt/lib/pe-puppet/lib/facter/windows.rb
Error: Could not retrieve catalog from remote server: SSL_connect
returned=1 errno=0 state=SSLv3 read server certificate B: certificate
verify failed: [self signed certificate in certificate chain for /CN=Puppet
CA generated on finnairportal.itcinfotech.com at 2013-09-24 14:13:35 +0530]
Warning: Not using cache on failed catalog
Error: Could not retrieve catalog; skipping run
Error: Could not send report: SSL_connect returned=1 errno=0 state=SSLv3
read server certificate B: certificate verify failed: [self signed
certificate in certificate chain for /CN=Puppet CA generated on
finnairportal.itcinfotech.com at 2013-09-24 14:13:35 +0530]
Server is getting request from client to server but after accepting request
agent no error throwing on server browser , but agent not disappearing on
server browser .
Regards
Ashish