Re: [Puppet Users] slight security problem

2011-03-14 Thread Mohamed Lrhazi
On Mon, Mar 14, 2011 at 2:36 AM, Michael Dodwell wrote: > Hey, > > > If i shutdown nginx and run the fetches via puppetmasterd I get > errors, as expected. > If you restart nginx, does the old client still work? Am guessing nginx needs to have access to, and use, an updated revocation list file, o

[Puppet Users] slight security problem

2011-03-13 Thread Michael Dodwell
Hey, Just wondering if anyone else has noticed this. I'm using thin+puppetmasterd+nginx. If i add a host, sign it's key, run puppetd successfully on it all is good, as expected. If i then revoke/clean the key on the master server, leave the box running, startup another host set the hostname to be