[chef] validation.pem seems to stop working after 24-48 hours.


Chronological Thread 
  • From: "Jason J. W. Williams" < >
  • To:
  • Subject: [chef] validation.pem seems to stop working after 24-48 hours.
  • Date: Mon, 16 May 2011 15:24:36 -0600
  • Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:date:message-id:subject:from:to:content-type; b=L0U/SymAhbZbcGF41UmTT+Z55NODcT4iZZFh5W1NSq06CGnnZBNab94j6AeTX0cPo0 v0mvtxfYF/4zNeH2R6iawsZQyzAIr5Hhq+pVMEvMyjEeT4IcV7X5A9fm2ZJMIPzHtjtQ o7ipvibMoLVowLK8qaPphfksBZUtzBoq8xXqA=

I've got a strange issue where my bootstraps start failing after using
the same validation.pem for more than 24-48 hours. The only way to fix
it is to do a "knife client regenerate" to generate a new private key.
Would really like to figure out why validation.pem stops working for
authentication after 24 hours. When I run "openssl rsa -in
validation.pem -pubout" I get the same public key that's listed in the
Chef WebUI for chef-validator. It's not a time sync problem, because
if I run knife with my own client key for my laptop, authentication is
fine, but the minute I do "-k validation.pem" I get 401 Unauthorized.
Any help is greatly appreciated. Regenerating chef-validator every 24
hours is getting old.

-J



Archive powered by MHonArc 2.6.16.

§