By far one of the dodgiest tasks in Cfengine is authentication of this
nature. Since the errors says 'denied access' then the trouble likely
lies in the access_rules server bundle. Do you have any such rules?
Example:
bundle server access_rules {
vars:
unxxhd01::
"ad
ived: [EXEC ] on socket 5
cf3 User root granted connection privileges
cf3 Host pixie.mallab.cert.org denied access to /
cf3 Server refusal due to denied access to requested object
cf3 From (host=pixie.mallab.cert.org,user=root,ip=:::10.27.41.199)
cf3 ID from