On Wed, Aug 6, 2014 at 12:28 AM, Juan Sierra Pons <j...@elsotanillo.net> wrote:
> 2014-08-05 23:23 GMT+02:00 Gabriel Filion <gabs...@lelutin.ca>: > > On 05/08/14 01:28 PM, Nan Liu wrote: > >> Please don't resign all client certificates. All you need to do is > >> recreate a puppet master certificate with dns alt name accepting both > >> the old and new puppet master hostname. Because passenger and other > >> configuration may already refer to the existing pem file name, it's > >> easier to just add the new hostname to the dns_alt_names accept list > > > > ah, thanks a lot for this. I was sure there was a more clever way to do > > this :) > > > > -- > > Gabriel Filion > > > > Hi, > > I didn't know it either. :) > > This drive me to ask a related question: Can the same approach be used > when the certificate expires? > Sure. Should work the same. Nan -- You received this message because you are subscribed to the Google Groups "Puppet Users" group. To unsubscribe from this group and stop receiving emails from it, send an email to puppet-users+unsubscr...@googlegroups.com. To view this discussion on the web visit https://groups.google.com/d/msgid/puppet-users/CACqVBqDigtq4A7VSKZB1Ttq3fqPuseiH4jb4dvSvfhcYjdv-wg%40mail.gmail.com. For more options, visit https://groups.google.com/d/optout.