Chicken/egg Policy-server/client

2012-02-07 Thread Pete Ashdown
I'm not finding detailed documentation on the CFengine site in regards to configuring both the policy-server and the client, I am most likely missing something, but the core question I have is if the policy-server has the same promises as the clients? In http://www.cfengine.com/manuals/cf3-solutio

Ubuntu 10.04 install

2011-12-23 Thread Pete Ashdown
Does anyone have cfengine3 working with multiple nodes with the default Ubuntu 10.04 packages? The Googles are failing me in finding any walkthroughs for 10.04 Ubuntu. I have a couple of issues. First when I run "cf-agent -v --bootstrap --policy-server (master IP address)" on a node, I get the e

Re: Master to client security, signing?

2011-12-22 Thread Pete Ashdown
On 12/22/2011 01:01 AM, Mark Burgess wrote: > On 12/21/2011 11:41 PM, Pete Ashdown wrote: >> One reason I've objected to the use of puppet in our organization is the >> lack of server to client security. That is, if the server is >> compromised, then in turn, all t

Master to client security, signing?

2011-12-21 Thread Pete Ashdown
One reason I've objected to the use of puppet in our organization is the lack of server to client security. That is, if the server is compromised, then in turn, all the clients are compromised. Before I start learning cfengine from scratch, I would like to know if and how this is addressed. Are