You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用外部证书的Puppet CSR问题求助:阻止Agent提交CSR

解决Puppet Agent持续提交CSR及CA服务禁用后的相关错误

问题背景

单服务器部署Puppet Server 7.28.0与Puppet Agent,使用外部签发的独立证书,但Agent仍尝试提交CSR;执行puppetserver ca list时出现SSL证书未知错误,Agent日志显示Failed to submit the CSR, HTTP response was 404。已通过ca.cfg禁用CA服务并在webserver.conf中指定外部证书路径。

解决方案

1. 配置Puppet Agent跳过证书请求流程

编辑Agent配置文件/etc/puppetlabs/puppet/puppet.conf,在[agent]段添加或修改以下配置,强制Agent使用已有的外部证书,停止生成和提交CSR:

[agent]
# 必须与Agent证书的Common Name完全匹配
certname = puppet.altserver.example.com
# 指定CA根证书路径
localcacert = /etc/puppetlabs/puppet/ssl/certs/ca.pem
# 指定Agent的证书文件路径
hostcert = /etc/puppetlabs/puppet/ssl/certs/server.altserver.example.com.pem
# 指定Agent的私钥文件路径
hostprivkey = /etc/puppetlabs/puppet/ssl/private_keys/server.altserver.example.com.pem
# 指定Puppet Server的主机名(需与Server证书中的SAN/CN匹配)
server = server.altserver.example.com
# 禁用等待证书签名的逻辑
waitforcert = 0
# 关闭自动证书请求行为
no_request = true

2. 清理Agent的CSR残留文件

删除Agent生成的证书请求文件,避免残留触发重复提交:

rm -rf /etc/puppetlabs/puppet/ssl/certificate_requests/*

3. 重启服务使配置生效

# 重启Puppet Agent
systemctl restart puppet
# 重启Puppet Server确保配置加载
systemctl restart puppetserver

4. 验证配置效果

执行Agent测试运行,检查是否仍有CSR相关错误:

/opt/puppetlabs/bin/puppet agent -t

若输出无CSR提交错误,且能正常与Server通信,则配置生效。

错误原因说明

  • puppetserver ca list报错:已通过ca.cfg禁用CA服务,Puppet Server不再提供/puppet-ca/v1端点,该命令无法使用属于正常现象,无需再执行。
  • Agent的404错误:Agent默认会向Server的CA端点提交CSR,但CA服务禁用后端点不存在,因此返回404;通过配置Agent使用现有证书并关闭请求逻辑即可解决。

额外注意事项

  • 确保所有证书文件的权限正确:证书目录及文件需归puppet:puppet所有,私钥权限设置为600,证书文件权限设置为644:
    chown -R puppet:puppet /etc/puppetlabs/puppet/ssl/
    chmod 600 /etc/puppetlabs/puppet/ssl/private_keys/*.pem
    chmod 644 /etc/puppetlabs/puppet/ssl/certs/*.pem
    
  • Agent的certname必须与证书的Common Name完全一致,否则会出现证书验证失败的错误。

内容的提问来源于stack exchange,提问作者Callum McCrorie

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.29 19:32:48