Well - as everything else - there can be security issues, where the SSL cert check won't help you: https://puppetlabs.com/security/cve/cve-2013-1640/
So you should definetely be careful - Puppet is very young, compared to apache, openssh and others that have been internetfacing for many, many years (and had their share of security bugs). I'd probably filter access to puppet, based on ip-ranges - just to heavily lessen the potential attacking base :) -- You received this message because you are subscribed to the Google Groups "Puppet Users" group. To unsubscribe from this group and stop receiving emails from it, send an email to puppet-users+unsubscr...@googlegroups.com. To post to this group, send email to puppet-users@googlegroups.com. Visit this group at http://groups.google.com/group/puppet-users?hl=en. For more options, visit https://groups.google.com/groups/opt_out.