[chef] Re: Re: validation.pem distribution question


Chronological Thread 
  • From: John Dewey < >
  • To:
  • Subject: [chef] Re: Re: validation.pem distribution question
  • Date: Wed, 19 Dec 2012 13:45:54 -0800

For hypervisors we distribute it via cobbler.

John

On Wednesday, December 19, 2012 at 1:43 PM, Daniel Condomitti wrote:

If you're creating nodes using knife bootstrap (or another plugin like knife ec2 or vsphere) the templates handle that for you.

(
cat <<'EOP'
<%= validation_key %>
EOP
) > /tmp/validation.pem
awk NF /tmp/validation.pem > /etc/chef/validation.pem
rm /tmp/validation.pem
chmod 0600 /etc/chef/validation.pem

On Wednesday, December 19, 2012 at 4:40 PM, Kirill Timofeev wrote:

Folks,

please share how do you distribute validation.pem. It looks this is
sensitive piece of data since anybody having it can register new client.
So it seems it is bad idea to make it available, for example, via http.
But how it can be provided for new client installation?

Thanks,
Kirill.





Archive powered by MHonArc 2.6.16.

§