Details
-
Bug
-
Status: Closed
-
Critical
-
Resolution: Duplicate
-
PUP 3.4.3
-
None
-
None
-
None
Description
In my tests puppet client never updates it’s /var/lib/puppet/ssl/crl.pem from the master when it changes.
Though the CRL is initially downloaded from a CA and ‘cached’ that cache is never cleared causing multi-master setups to run with an increasingly outdated CRL.
I think this bug is dangerous especially because the separate CA thing is new and people don’t realize, nor is it documented, that this is the current behavior.
Attachments
Issue Links
- duplicates
-
PUP-2310 Puppet client does not update and does consult the crl during authentication
-
- Resolved
-