I'm trying to create an autosign policy which checks for a custom attribute
in the CSR but I'm having some issue with the master not signing the
My client has the following in /etc/puppet/csr_attributes.yaml
My policy is a simple bash script, in this case checking for foo
CUSTOM_ATTR=$(echo "$(cat)" | grep "challengePassword" | awk -F ":"
if [[ "$CUSTOM_ATTR" == "foo" ]]
I had tested with the following, I'm guessing the issue is with my script
not reading in the CSR from puppet? If anyone has any examples of policies
they have created I would love to see them (this seems to be lacking in the
sudo openssl req -noout -text -in
/var/lib/puppet/ssl/ca/requests/mynode.pem | /etc/puppet/autosign.sh; echo
You received this message because you are subscribed to the Google Groups "Puppet Users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to email@example.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/puppet-users/30d1d249-b648-4eb2-be32-1578f6118705%40googlegroups.com.
For more options, visit https://groups.google.com/groups/opt_out.