Uploaded image for project: 'Documentation'
  1. Documentation
  2. DOCUMENT-59

External CA - Support for CRL - Documentation Update

    Details

    • Type: Bug
    • Status: Closed
    • Priority: Normal
    • Resolution: Done
    • Component/s: Puppet Language
    • Labels:
      None
    • Template:
    • Story Points:
      2
    • Sprint:
      Killer Kakapo 1.19.15
    • UX Priority:
      Normal

      Description

      The documentation on setting up an external CA makes the following statement:

      Certificate revocation list (CRL) checking works in all three supported configurations, so long as the CRL file is distributed to the agents and masters using an “out of band” process. Puppet won’t automatically update the CRL on any of the components in the system.

      See http://docs.puppetlabs.com/puppet/latest/reference/config_ssl_external_ca.html#revocation

      This is not true for "Option 3: Two Intermediate CAs Issued by One Root CA" since a Puppet agent cannot support multiple CRLs, which is required in the event there is a certificate chain.

      The documentation should be updated to state that CRLs on the agent are not supported for "Option 3: Two Intermediate CAs Issued by One Root CA."

      Option 3 should include additional documentation to set "certificate_revocation = false" on all Puppet agents. The documentation for "certificate_revocation" states the following

      certificate_revocation
      Whether certificate revocation should be supported by downloading a Certificate Revocation List (CRL) to all clients. If enabled, CA chaining will almost definitely not work.
      Default: true

      See http://docs.puppetlabs.com/references/latest/configuration.html#certificaterevocation

      This should be included as a cross-reference or cited on the external CA page.

        Attachments

          Issue Links

            Activity

              jsd-sla-details-panel

                People

                • Assignee:
                  garrett.guillotte Garrett Guillotte
                  Reporter:
                  agrams Axton Grams
                • Votes:
                  2 Vote for this issue
                  Watchers:
                  7 Start watching this issue

                  Dates

                  • Created:
                    Updated:
                    Resolved: