You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ubuntu 22.04环境下Puppet Agent证书验证失败问题求助

Puppet Agent证书验证失败(unable to get issuer certificate)解决办法

1. 核对Agent与Server端CA证书一致性

  • 查看Agent端CA证书路径:/etc/puppetlabs/puppet/ssl/certs/ca.pem
  • 将Server端的CA证书(路径:/etc/puppetlabs/puppet/ssl/certs/ca.pem)复制到Agent对应路径,用diff命令确认两者完全一致:
    diff /etc/puppetlabs/puppet/ssl/certs/ca.pem /path/to/copied/server-ca.pem
    
  • 若不一致,覆盖Agent端CA证书后重启Agent服务:
    systemctl restart puppet
    

2. 确认Agent配置中CA服务器指向正确

  • 编辑/etc/puppetlabs/puppet/puppet.conf,检查[agent]段的server和ca_server配置,确保指向Puppet Server的正确主机名或IP:
    [agent]
    server = puppetserver01
    ca_server = puppetserver01
    
  • 可临时改用IP地址测试,排除主机名解析潜在问题(即使已检查DNS,也可在/etc/hosts手动添加Server映射)

3. 修复Server端CA证书链异常

  • 在Server端执行以下命令,检查CA证书的Issuer与Subject是否一致(自签CA两者应完全相同):
    openssl x509 -in /etc/puppetlabs/puppet/ssl/certs/ca.pem -text -noout | grep -E "Issuer|Subject"
    
  • 若不一致,重新初始化CA:
    puppetserver ca clean --all
    puppetserver setup
    systemctl restart puppetserver
    
  • 之后在Agent端重新请求证书:
    puppet agent -t --waitforcert 60
    
  • 回到Server端完成签名:
    puppetserver ca sign --all
    

4. 修正Agent端SSL目录权限

  • 确保SSL目录及子文件的所有者为puppet用户:
    chown -R puppet:puppet /etc/puppetlabs/puppet/ssl
    chmod -R 750 /etc/puppetlabs/puppet/ssl
    

5. 强制Agent重新拉取CA证书

  • 删除Agent端旧的CA证书及CRL文件:
    rm -rf /etc/puppetlabs/puppet/ssl/certs/ca.pem /etc/puppetlabs/puppet/ssl/crl.pem
    
  • 执行以下命令强制重新获取CA证书:
    puppet agent -t --ca_server puppetserver01
    

内容的提问来源于stack exchange,提问作者Med

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.01 22:03:14