Hi

working my way through a puppet install. Working on my external node 
classifier. Found this

puppet facts <certname>

Seems like I can run this from any machine and it queries the DB and return 
me information about that node.  Seems like a bit of a security leak... 
from my windows machine I can see the entire setup of a my production 
servers just by naming them here.

Is there any way to limit who | what gets sent back. could you limit it 
such that the calling (client) can only see info about its self and noone 
else ? I suppose how to you allow the puppet master to do it then 


Alex

-- 
You received this message because you are subscribed to the Google Groups 
"Puppet Users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to puppet-users+unsubscr...@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/puppet-users/4f19c47a-d90a-4c9b-9a95-10d1f59f1826%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.

Reply via email to