On Friday, March 10, 2017 at 10:28:06 AM UTC, waz0wski wrote: Are you hard-set on using Vault? >
No, but it have features that I'm interested in exploring more. Such as the SSH OTP backend. I could see myself using that at least. > I use FreeIPA <https://www.freeipa.org/page/Main_Page>, which includes > PKI management (via Dogtag > <http://pki.fedoraproject.org/wiki/PKI_Main_Page>), and can be used as > the CA for puppet and also issue the per-node certs. > I've only heard about FreeIPA in passing. I'll have a look at it, thanx! > Technically, Foreman > <https://www.google.com/url?q=https%3A%2F%2Ftheforeman.org%2Fintroduction.html&sa=D&sntz=1&usg=AFQjCNHncsrPNTCWu1gRoaK1ctKUBh293w> > is > doing the work for me > Sounds a little like MCOllective (?) - which I'm currently using (with great success I might add). -- You received this message because you are subscribed to the Google Groups "Puppet Users" group. To unsubscribe from this group and stop receiving emails from it, send an email to puppet-users+unsubscr...@googlegroups.com. To view this discussion on the web visit https://groups.google.com/d/msgid/puppet-users/6c5f6830-8cc2-4c59-bd35-a643582959f0%40googlegroups.com. For more options, visit https://groups.google.com/d/optout.