On Tuesday, November 18, 2014 7:57:44 AM UTC-6, Roger Sherman wrote: > > For some reason, (I think) the PM is unable to sign them. At least, that's > what seems to be the case. >
Well yes, sort of. It appears that the PM is unable to sign the requests because the client is unable to establish a secure connection over which to *issue* the request in the first place. (The client doesn't need its own cert for that. The client cert is for the client to prove its identity to the master, which it doesn't need to do to request cert signing.) John -- You received this message because you are subscribed to the Google Groups "Puppet Users" group. To unsubscribe from this group and stop receiving emails from it, send an email to puppet-users+unsubscr...@googlegroups.com. To view this discussion on the web visit https://groups.google.com/d/msgid/puppet-users/944269b4-651a-4372-a22d-f2a66edb3d1d%40googlegroups.com. For more options, visit https://groups.google.com/d/optout.