傀儡证书捕获错误

傀儡证书捕获错误

安装 puppet master 和客户端后,当我请求目录时,出现以下错误:

[root@INFINI-ONE puppet]# puppet agent -t
warning: peer certificate won't be verified in this SSL session
info: Caching certificate for infini-one.infinicluster
err: Could not retrieve catalog from remote server: Error 400 on SERVER: No 
support for http method POST
warning: Not using cache on failed catalog
err: Could not retrieve catalog; skipping run

然后:

[root@INFINI-ONE puppet-2.7.14]# puppet agent -t
warning: peer certificate won't be verified in this SSL session
warning: peer certificate won't be verified in this SSL session
info: Caching certificate for infini-one.infinicluster
err: Could not retrieve catalog from remote server: SSL_connect returned=1 
errno=0 state=SSLv3 read server certificate B: certificate verify failed.  This 
is often because the time is out of sync on the server or client
warning: Not using cache on failed catalog
err: Could not retrieve catalog; skipping run
err: Could not send report: SSL_connect returned=1 errno=0 state=SSLv3 read 
server certificate B: certificate verify failed.  This is often because the 
time is out of sync on the server or client

答案1

客户端和服务器是否使用相同的 Puppet 版本?如果您使用的是两个不同的操作系统,这一点对于验证这一点尤为重要。

您可能会发现此链接很有帮助:http://bitcube.co.uk/content/puppet-errors-explained

答案2

当 puppetmaster 和客户端之间的时间不同步时,通常会出现此问题。

您检查过两个服务器上的时间是否相同?

如果客户端在生成证书时落后,则客户端会看到证书的开始日期是将来的日期,因此无效。

相关内容