Re: [Puppet Users] X509v3 Subject Alternative Name in puppet generated certs...

2012-03-12 Thread Jonathan Proulx
Hi Nigel, Thanks for the fabulous response. I was convinced I was going to need to do this by hand, happy to see my native pessimism proved wrong. On Sat, Mar 10, 2012 at 4:23 PM, Nigel Kersten ni...@puppetlabs.com wrote: Jon, what version of Puppet are you running? 2.7.11 on Debian/Squeeze

Re: [Puppet Users] X509v3 Subject Alternative Name in puppet generated certs...

2012-03-10 Thread Nigel Kersten
On Fri, Mar 9, 2012 at 6:15 PM, Jonathan Proulx j...@jonproulx.com wrote: I'm OK with flushing all my certs and starting over, but I have a couple of questions.  How does the puppet CA populate the altName field? and can I make it do what I want for both the CA and the non-CA servers or do I

[Puppet Users] X509v3 Subject Alternative Name in puppet generated certs...

2012-03-09 Thread Jonathan Proulx
I'm trying to split out my certificate authority and have one CA and multiple masters, currently using round robin DNS, possibly using HAproxy later. Got most of the way there but tangled up in names and certificates. When the Puppet CA generated it's certificate the PTR record for it's IP