Puppet Dashboard启动失败:需向Puppet Master生成SHA256证书求助
Alright, let’s sort out this certificate mismatch issue that’s blocking your Puppet Dashboard from starting. I’ve dealt with this exact problem before, so here’s a straightforward, step-by-step fix:
Step 1: Clean up old MD5 certificates on the Dashboard server
First, we need to get rid of the invalid MD5-signed certificates that your Puppet Master refuses to sign:
- Run these commands to remove existing cert files (replace
<your-dashboard-fqdn>with your Dashboard server’s fully qualified domain name):puppet cert clean <your-dashboard-fqdn> rm -rf /var/lib/puppet/ssl/certs/<your-dashboard-fqdn>.pem rm -rf /var/lib/puppet/ssl/private_keys/<your-dashboard-fqdn>.pem rm -rf /var/lib/puppet/ssl/public_keys/<your-dashboard-fqdn>.pem
Step 2: Configure the Dashboard to generate SHA256 certificate requests
Next, we’ll force the Dashboard’s Puppet agent to use SHA256 for all certificate operations:
- Open your
puppet.conffile (typically at/etc/puppet/puppet.confor/etc/puppetlabs/puppet/puppet.confdepending on your setup) - Add or update the
digest_algorithmsetting in the[agent]section:[agent] digest_algorithm = sha256 - Restart the Puppet agent service to apply the change:
# For systemd-based systems systemctl restart puppet # For SysVinit systems service puppet restart - Generate a new SHA256 certificate request and wait for the Master to pick it up:
puppet agent -t --waitforcert 60
Step 3: Sign the SHA256 certificate on the Puppet Master
Head back to your Puppet Master server to process the valid cert request:
- List pending certificate requests to confirm the Dashboard’s request is now available (it should use SHA256):
You can double-check the algorithm withpuppet cert listpuppet cert print <your-dashboard-fqdn>if you want to be thorough. - Sign the valid SHA256 certificate request:
puppet cert sign <your-dashboard-fqdn>
Step 4: Verify connectivity and start the Dashboard
Return to the Dashboard server to wrap things up:
- Run the Puppet agent again to pull the signed certificate:
puppet agent -t - Start the Puppet Dashboard UI service and confirm it runs successfully:
# Start the service systemctl start puppet-dashboard # Check status to confirm it's running systemctl status puppet-dashboard
A quick extra note: Since your Dashboard acts as a proxy for the Puppet Master, make sure your Master’s auth.conf or main Puppet config allows the Dashboard server to access necessary endpoints—this avoids hidden permission issues that might crop up later.
内容的提问来源于stack exchange,提问作者Vasanth Nag K V

